git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: security flaw with smart http

From
IKIvan Kanis <ivan.kanis@googlemail.com>
Date
Jun 28, 2012, 07:35 UTC
Message-ID
<87obo3j3d0.fsf@visionobjects.com>
In-Reply-To
<7vmx3vp2co.fsf@alter.siamese.dyndns.org>
Junio C Hamano <gitster@pobox.com> a écrit
Show 12 quoted lines
> Shawn Pearce <spearce@spearce.org> writes:
>
>> On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
>>> I think we found a security flaw with git http smart backend. We are
>>> running git version 1.0.7.4 on our server. Adding random words after the
>>> password and the authentication still succeeds.
>>
>> git http-backend does not handle authentication or authorization. This
>> is handled in your web server. You should consult your web server's
>> documentation, and maybe its configuration files.
>
> Very good advice.

In case someone is reading this thread I confirm the problem comes from Apache.

-- 
Ivan Kanis, Release Manager, Vision Objects,

Le mal est un mulet : il est opiniâtre et stérile.
    -- Victor Hugo
Previous: Erik Faye-Lund
Message 7 of 7 in “security flaw with smart http”
  1. Ivan KanisJun 22, 2012
  2. Shawn PearceJun 22, 2012
  3. Junio C HamanoJun 22, 2012
  4. Philippe VaucherJun 25, 2012
  5. Ivan KanisJun 25, 2012
  6. Erik Faye-LundJun 25, 2012
  7. Ivan KanisJun 28, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.