git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* security flaw with smart http
@ 2012-06-22 10:12 Ivan Kanis
  2012-06-22 17:54 ` Shawn Pearce
  0 siblings, 1 reply; 7+ messages in thread
From: Ivan Kanis @ 2012-06-22 10:12 UTC (permalink / raw)
  To: Git Mailing List

Hi,

I think we found a security flaw with git http smart backend. We are
running git version 1.0.7.4 on our server. Adding random words after the
password and the authentication still succeeds. 

It's very easy to reproduce, say the username is ivan and the password
is the word secret:

% git pull
Username: ivan
Password: secretfoo
Already up to date.

Pull succeeds although the password is wrong! Can someone try to
reproduce with a more up to date git server?
-- 
Ivan Kanis
http://ivan.kanis.fr

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2012-06-28  7:35 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-06-22 10:12 security flaw with smart http Ivan Kanis
2012-06-22 17:54 ` Shawn Pearce
2012-06-22 19:34   ` Junio C Hamano
2012-06-25 11:24     ` Philippe Vaucher
2012-06-25 12:59       ` Ivan Kanis
2012-06-25 13:10         ` Erik Faye-Lund
2012-06-28  7:35     ` Ivan Kanis

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).