Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an attacker controls the central Git server or one of the other members' machines, and also controls one of the services already in the password store, they can rename one of the password files in the Git repository to something else: pass doesn't correctly verify that the content of a file matches the filename, so a user might be tricked into decrypting the wrong password and sending that to a service that the attacker controls. NOTE: for environments in which this threat model is of concern, signing commits can be a solution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Git 授权问题漏洞
Vulnerability Description
Git是一套免费、开源的分布式版本控制系统。 Git 1.7.3版本存在授权问题漏洞,该漏洞源于可以为意外资源使用密码。为了进行利用,用户必须执行一次git pull操作,解密密码,并使用密码登录到远程服务。如果攻击者可利用该漏洞控制中央Git服务器或其他成员的一个机器,并控制服务已经在密码存储之一,他们可以重命名一个Git仓库密码文件的其他东西:通过不正确的验证文件的内容匹配的文件名,那么用户可能会骗解密和发送错误的密码
CVSS Information
N/A
Vulnerability Type
N/A