INFBA-2024:3053: git-lfs security update

Information about definition

Identificator: INFBA-2024:3053

Type: bugfix

Release date: 2025-03-05 15:29:36 UTC

Information about package

Git LFS is a command line extension and specification for managing large files with Git.

Vulnerabilities description

  • CVE-2023-29406

    A flaw was found in Golang, where it is vulnerable to HTTP header injection caused by improper content validation of the Host header by the HTTP/1 client. A remote attacker can inject arbitrary HTTP headers by persuading a victim to visit a specially crafted Web page. This flaw allows the attacker to conduct various attacks against the vulnerable system, including Cross-site scripting, cache poisoning, or session hijacking.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 6.5 no information
Critical, important, moderate, low

Updated packages

loader icon Preparing to download...
Architecture: Download