git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.
CPE | Name | Operator | Version |
---|---|---|---|
git | eq | 1.8.1.1 | |
git | eq | 2.25.1-r0 | |
git | eq | gitgui-0.6.0 | |
git | eq | 1.6.1-rc1 | |
git | eq | 1.4.0 | |
git | eq | 1.7.10.1-r0 | |
git | eq | 1.7.12.2-r0 | |
git | eq | 1.6.2.3-r0 | |
git | eq | 1.9.2-r0 | |
git | eq | 1.6.6.3 |