#VU102870 Improper Encoding or Escaping of Output in Git - CVE-2024-50349
Published: January 16, 2025
Git
Git
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect handling of control sequences in account names when asking for credentials. A remote attacker can trick the victim into clicking on a specially crafted URL and trick users into providing passwords for trusted Git hosting sites when in fact they are then sent to untrusted sites that are under the attacker's control.