Sabuntawar Git tare da gyara wani lahani

Buga gyare-gyare na tsarin sarrafa tushen rarraba Git 2.26.2, 2.25.4, 2.24.3, 2.23.3, 2.22.4, 2.21.3, 2.20.4, 2.19.5, 2.18.4 da 2.17.5, in wanda ya kawar rauni (CVE-2020-11008), tunawa matsala, kawar da makon da ya gabata. Sabuwar lalura kuma tana shafar masu amfani da "credential.helper" kuma ana amfani da ita lokacin wuce URL ɗin da aka tsara musamman wanda ke ɗauke da sabon layi, mai masaukin baki, ko tsarin buƙatun da ba a bayyana ba. Lokacin sarrafa irin wannan URL ɗin, credential.helper yana aika bayanai game da takaddun shaida waɗanda basu dace da ƙa'idar da aka nema ba ko kuma ana isa ga mai watsa shiri.

Ba kamar matsalar da ta gabata ba, lokacin da ake amfani da sabon rauni, maharin ba zai iya sarrafa mai masaukin kai tsaye wanda za a canja wurin shaidar wani ba. Waɗanne takaddun shaida da aka fallasa ya dogara da yadda ake sarrafa siginar “host” da ya ɓace a cikin takardar shaidar.helper. Tushen matsalar ita ce filayen da ba komai a cikin URL ana fassara su da yawa ta masu amfani da masu taimakawa a matsayin umarni don amfani da kowane takaddun shaida ga buƙatun na yanzu. Don haka, credential.helper zai iya aika bayanan shaidar da aka adana don wani sabar zuwa uwar garken maharin da aka ƙayyade a cikin URL.

Matsalar tana faruwa a lokacin da ake gudanar da ayyuka kamar "git clone" da "git fetch", amma ya fi haɗari lokacin sarrafa ƙananan ƙwayoyin cuta - lokacin yin "git submodule update", URLs da aka ƙayyade a cikin fayil ɗin .gitmodules daga ma'ajiyar ana sarrafa ta atomatik. A matsayin mafita don toshe matsalar shawarar Kar a yi amfani da credential.helper lokacin shiga ma'ajiyar jama'a kuma kar a yi amfani da "git clone" a yanayin "--recurse-submodules" tare da ma'ajiyar da ba a bincika ba.

An ba da shi a cikin sabbin abubuwan Git gyara yana hana kiran credential.helper don URLs masu ɗauke da su dabi'u marasa wakilci (misali, lokacin da ake ƙayyade sassa uku maimakon biyu - "http:///host" ko kuma ba tare da tsarin yarjejeniya ba - "http::ftp.example.com/"). Matsalar tana shafar shagon masu sarrafa bayanai (ajiyar bayanan da aka gina a ciki ta Git), cache (ajiyar bayanan da aka shigar a ciki) da osxkeychain (ajiyar bayanai don macOSMai kula da Git Credential Manager (ma'ajiyar ajiya don Windows) ba ya fuskantar rauni.

Kuna iya bin diddigin sakin sabuntawar fakiti a cikin rabawa akan shafuka Debian, Ubuntu, RHEL, SUSE/budeSUSE, Fedora, Arch, Alt, FreeBSD.

source: budenet.ru

Sayi amintaccen masauki don shafuka tare da kariyar DDoS, sabar VPS VDS 🔥 Sayi ingantaccen masaukin yanar gizo tare da kariyar DDoS, sabar VPS VDS | ProHoster