GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs

Post Reply
Shane1145
Posts: 1689
Joined: Wed Sep 25, 2024 2:31 pm

GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs

Post by Shane1145 »

Multiple security vulnerabilities have been disclosed in GitHub Desktop as well as other Git-related projects that, if successfully exploited, could permit an attacker to gain unauthorized access to a user's Git credentials.

"Git implements a protocol called Git Credential Protocol to retrieve credentials from the credential helper," GMO Flatt Security researcher Ry0taK, who discovered the flaws, said in an analysis published Sunday. "Because of improper handling of messages, many projects were vulnerable to credential leakage in various ways."

https://thehackernews.com/2025/01/githu ... risks.html
Post Reply