| module: github.com/git-lfs/git-lfs |
| package: github.com/git-lfs/git-lfs/commands |
| - module: github.com/git-lfs/git-lfs |
| package: github.com/git-lfs/git-lfs/creds |
| - AskPassCredentialHelper.getFromProgram |
| - commandCredentialHelper.Approve |
| - fixed: v1.5.1-0.20210113180018-fc664697ed2c |
| - module: github.com/git-lfs/git-lfs |
| package: github.com/git-lfs/git-lfs/lfs |
| - fixed: v1.5.1-0.20210113180018-fc664697ed2c |
| - module: github.com/git-lfs/git-lfs |
| package: github.com/git-lfs/git-lfs/lfshttp |
| - fixed: v1.5.1-0.20210113180018-fc664697ed2c |
| - fixed: v1.5.1-0.20210113180018-fc664697ed2c |
| Due to the standard library behavior of exec.LookPath on Windows a number of methods may |
| result in arbitary code execution when cloning or operating on untrusted Git repositories. |
| published: 2021-04-14T12:00:00Z |
| commit: https://github.com/git-lfs/git-lfs/commit/fc664697ed2c2081ee9633010de0a7f9debea72a |
| - https://github.com/git-lfs/git-lfs/security/advisories/GHSA-cx3w-xqmc-84g5 |