The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.
https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/
https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/
Published: 2022-02-11
Updated: 2024-11-21
Named Vulnerability: GitbleedNamed Vulnerability: GitBleed
Base Score: 4.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.00812