CVE-2021-40330

HIGH

Git <2.30.1 - SSRF

Title source: llm
STIX 2.1

Description

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0045
EPSS Percentile 63.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
debian/debian_linux 10.0
git-scm/git < 2.30.1
Published Aug 31, 2021
Tracked Since Feb 18, 2026