git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: security flaw with smart http

From
Shawn Pearce <spearce@spearce.org>
Date
Jun 22, 2012, 17:54 UTC
Message-ID
<CAJo=hJvCC8_oFFMyc5Fkweg6A6cSV6z+UxeCkvnU34KQfYx91w@mail.gmail.com>
In-Reply-To
<87fw9ns0cp.fsf@kanis.fr>
On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
> I think we found a security flaw with git http smart backend. We are
> running git version 1.0.7.4 on our server. Adding random words after the
> password and the authentication still succeeds.

git http-backend does not handle authentication or authorization. This is handled in your web server. You should consult your web server's documentation, and maybe its configuration files.

Show 10 quoted lines
> It's very easy to reproduce, say the username is ivan and the password
> is the word secret:
>
> % git pull
> Username: ivan
> Password: secretfoo
> Already up to date.
>
> Pull succeeds although the password is wrong! Can someone try to
> reproduce with a more up to date git server?

Git is freely available under the GPLv2 license. I believe it is possible for you to attempt experiments yourself with more up-to-date versions if you wish.

Previous: Ivan KanisNext: Junio C Hamano
Message 2 of 7 in “security flaw with smart http”
  1. Ivan KanisJun 22, 2012
  2. Shawn PearceJun 22, 2012
  3. Junio C HamanoJun 22, 2012
  4. Philippe VaucherJun 25, 2012
  5. Ivan KanisJun 25, 2012
  6. Erik Faye-LundJun 25, 2012
  7. Ivan KanisJun 28, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.