In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade git-credential-manager
to version 2.6.1 or higher.
Affected versions of this package are vulnerable to Interpretation Conflict due to improper handling of newline characters in remote URLs. An attacker can capture credentials for another Git remote by crafting a malicious URL that manipulates newline interpretations between Git and the Git Credential Manager.
Only interact with trusted remote repositories, and do not clone with --recursive
to allow inspection of any submodule URLs before cloning those submodules.
https://\rhost=targethost@badhost