SCA: security update for git-credential-manager (GHSA-86c2-4x57-wc8g)

high Tenable Self-Hosted Container Security Plugin ID 412472

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS,
and Linux. The Git credential protocol is text-based over standard input/output, and consists of a series
of lines of key-value pairs in the format `key=value`. Git's documentation restricts the use of the NUL
(`\0`) character and newlines to form part of the keys or values. When Git reads from standard input, it
considers both LF and CRLF as newline characters for the credential protocol by virtue of calling
`strbuf_getline` that calls to `strbuf_getdelim_strip_crlf`. Git also validates that a newline is not
present in the value by checking for the presence of the line-feed character (LF, `\n`), and errors if
this is the case. This captures both LF and CRLF-type newlines. Git Credential Manager uses the .NET
standard library `StreamReader` class to read the standard input stream line-by-line and parse the
`key=value` credential protocol format. The implementation of the `ReadLineAsync` method considers LF,
CRLF, and CR as valid line endings. This is means that .NET considers a single CR as a valid newline
character, whereas Git does not. This mismatch of newline treatment between Git and GCM means that an
attacker can craft a malicious remote URL. When a user clones or otherwise interacts with a malicious
repository that requires authentication, the attacker can capture credentials for another Git remote. The
attack is also heightened when cloning from repositories with submodules when using the `--recursive`
clone option as the user is not able to inspect the submodule remote URLs beforehand. This issue has been
patched in version 2.6.1 and all users are advised to upgrade. Users unable to upgrade should only
interact with trusted remote repositories, and not clone with `--recursive` to allow inspection of any
submodule URLs before cloning those submodules. (CVE-2024-50338)

See Also

https://github.com/advisories/GHSA-86c2-4x57-wc8g

Plugin Details

Severity: High

ID: 412472

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 51.01

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2024-50338

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2025

Vulnerability Publication Date: 1/14/2025

Reference Information

CVE: CVE-2024-50338