diff --git a/advisories/github-reviewed/2025/01/GHSA-86c2-4x57-wc8g/GHSA-86c2-4x57-wc8g.json b/advisories/github-reviewed/2025/01/GHSA-86c2-4x57-wc8g/GHSA-86c2-4x57-wc8g.json new file mode 100644 index 00000000000..f744e2882d7 --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-86c2-4x57-wc8g/GHSA-86c2-4x57-wc8g.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86c2-4x57-wc8g", + "modified": "2025-01-14T19:40:54Z", + "published": "2025-01-14T19:40:54Z", + "aliases": [ + "CVE-2024-50338" + ], + "summary": "Git Credential Manager carriage-return character in remote URL allows malicious repository to leak credentials", + "details": "### Description\nThe [Git credential protocol](https://git-scm.com/docs/git-credential#IOFMT) is text-based over standard input/output, and consists of a series of lines of key-value pairs in the format `key=value`. Git's documentation restricts the use of the NUL (`\\0`) character and newlines to form part of the keys[^1] or values.\n\nWhen Git reads from standard input, it considers both LF and CRLF[^2] as newline characters for the credential protocol by virtue of [calling `strbuf_getline`](https://github.com/git/git/blob/6a11438f43469f3815f2f0fc997bd45792ff04c0/credential.c#L311) that calls to `strbuf_getdelim_strip_crlf`. Git also validates that a newline is not present in the value by checking for the presence of the line-feed character (LF, `\\n`), and errors if this is the case. This captures both LF and CRLF-type newlines.\n\nGit Credential Manager uses the .NET standard library [`StreamReader`](https://learn.microsoft.com/en-us/dotnet/api/system.io.streamreader?view=net-8.0) class to [read the standard input stream line-by-line](https://github.com/git-ecosystem/git-credential-manager/blob/ae009e11a0fbef804ad9f78816d84a0bc7e052fe/src/shared/Core/StreamExtensions.cs#L138-L141) and parse the `key=value` credential protocol format. The [implementation of the `ReadLineAsync` method](https://github.com/dotnet/runtime/blob/e476b43b5cb42eb44ce23b1c7b793aa361624cf6/src/libraries/System.Private.CoreLib/src/System/IO/StreamReader.cs#L926) considers LF, CRLF, and CR as valid line endings. This is means that .NET considers a single CR as a valid newline character, whereas Git does not.\n\nThis mismatch of newline treatment between Git and GCM means that an attacker can craft a malicious remote URL such as:\n\n```\nhttps://\\rhost=targethost@badhost\n```\n\n..which will be interpreted by Git as:\n\n```\nprotocol=https\nhost=badhost\nusername=\\rhost=targethost\n```\n\nThis will instead be parsed by GCM as if the following has been passed by Git:\n\n```\nprotocol=https\nhost=badhost\nusername=\nhost=targethost\n```\n\nThis results in the `host` field being resolved to the `targethost` value. GCM will then return a credential for `targethost` to Git, which will then send this credential to the `badhost` host.\n\n### Impact\nWhen a user clones or otherwise interacts[^3] with a malicious repository that requires authentication, the attacker can capture credentials for another Git remote. The attack is also heightened when cloning from repositories with submodules when using the `--recursive` clone option as the user is not able to inspect the submodule remote URLs beforehand.\n\n### Patches\nhttps://github.com/git-ecosystem/git-credential-manager/compare/749e287571c78a2b61f926ccce6a707050871ab8...99e2f7f60e7364fe807e7925f361a81f3c47bd1b\n\n### Workarounds\nOnly interacting with trusted remote repositories, and do not clone with `--recursive` to allow inspection of any submodule URLs before cloning those submodules.\n\n### Fixed versions\nThis issue is fixed as of [version 2.6.1](https://github.com/git-ecosystem/git-credential-manager/releases/tag/v2.6.1).\n\n[^1]: The `=` character is also forbidden to form part of the key.\n[^2]: Carriage-return character (CR, `\\r`), followed by a line-feed character.\n[^3]: Any remote operation such as `fetch`, `ls-remote`, etc.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "NuGet", + "name": "git-credential-manager" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.6.1" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2.6.0" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/git-ecosystem/git-credential-manager/security/advisories/GHSA-86c2-4x57-wc8g" + }, + { + "type": "PACKAGE", + "url": "https://github.com/git-ecosystem/git-credential-manager" + }, + { + "type": "WEB", + "url": "https://github.com/git-ecosystem/git-credential-manager/compare/749e287571c78a2b61f926ccce6a707050871ab8...99e2f7f60e7364fe807e7925f361a81f3c47bd1b" + }, + { + "type": "WEB", + "url": "https://github.com/git-ecosystem/git-credential-manager/releases/tag/v2.6.1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-436" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-01-14T19:40:54Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-9v8m-qv22-f268/GHSA-9v8m-qv22-f268.json b/advisories/github-reviewed/2025/01/GHSA-9v8m-qv22-f268/GHSA-9v8m-qv22-f268.json new file mode 100644 index 00000000000..b94c4a59f5b --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-9v8m-qv22-f268/GHSA-9v8m-qv22-f268.json @@ -0,0 +1,113 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v8m-qv22-f268", + "modified": "2025-01-14T19:41:48Z", + "published": "2025-01-14T19:41:48Z", + "aliases": [ + "CVE-2025-23041" + ], + "summary": "Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length", + "details": "### Impact\n\nCharacter limits configured by editors for short and long answer fields are validated only client-side, not server-side.\n\n### Patches\n\nPatched in 8.13.16, 10.5.7, 13.2.2, 14.1.2\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Forms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "10.5.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "UmbracoForms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.13.16" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 8.13.15" + } + }, + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Forms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "11.0.0-rc1" + }, + { + "fixed": "13.2.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Forms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "14.0.0-beta001" + }, + { + "fixed": "14.1.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-9v8m-qv22-f268" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-14T19:41:48Z", + "nvd_published_at": null + } +} \ No newline at end of file