summaryrefslogtreecommitdiff
path: root/compat/regex/regexec.c
diff options
context:
space:
mode:
authorJohannes Schindelin <johannes.schindelin@gmx.de>2024-10-29 23:52:11 +0100
committerJohannes Schindelin <johannes.schindelin@gmx.de>2024-11-26 22:14:45 +0100
commit08756131a3b7038a60365ae56804cea4301082a9 (patch)
tree1b1ef503233ddfcb23686e0cd415f008bf35631a /compat/regex/regexec.c
parent062d9fb033ec994305343bb28dbad3c2f799de47 (diff)
parentb01b9b81d36759cdcd07305e78765199e1bc2060 (diff)
Merge branch 'disallow-control-characters-in-credential-urls-by-default'
This addresses two vulnerabilities: - CVE-2024-50349: Printing unsanitized URLs when asking for credentials made the user susceptible to crafted URLs (e.g. in recursive clones) that mislead the user into typing in passwords for trusted sites that would then be sent to untrusted sites instead. - CVE-2024-52006 Git may pass on Carriage Returns via the credential protocol to credential helpers which use line-reading functions that interpret said Carriage Returns as line endings, even though Git did not intend that. Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Diffstat (limited to 'compat/regex/regexec.c')
0 files changed, 0 insertions, 0 deletions