Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:1518 - Security Advisory
Issued:
2020-04-21
Updated:
2020-04-21

RHSA-2020:1518 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: git security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for git is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.

Security Fix(es):

  • git: Crafted URL containing new lines can cause credential leak (CVE-2020-5260)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.0 x86_64

Fixes

  • BZ - 1822020 - CVE-2020-5260 git: Crafted URL containing new lines can cause credential leak

CVEs

  • CVE-2020-5260

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.0

SRPM
git-2.18.2-2.el8_0.src.rpm SHA-256: 4219c298d36011f6eac81c6c9f0fdaa06b2b8bea5446f8a9e7a3469f1515b392
ppc64le
git-2.18.2-2.el8_0.ppc64le.rpm SHA-256: 31b398d1045db0a8c48b7de3d61bb1d671e259cd2f5e16d566300de3c2471932
git-all-2.18.2-2.el8_0.noarch.rpm SHA-256: 869070b1000b681e55f09a0b922d3f411fd209a0418b1f81bf122fbcff444215
git-core-2.18.2-2.el8_0.ppc64le.rpm SHA-256: f354768ad165e4fb3dd5fabc28b267c4abbea1c15c1fe84af0dbc4cbcb247b4b
git-core-debuginfo-2.18.2-2.el8_0.ppc64le.rpm SHA-256: 72fb3e8912776c72adf02e5f873c55dba4a809d97e2e20a9c7fb3a9c8fd01cad
git-core-doc-2.18.2-2.el8_0.noarch.rpm SHA-256: c22d43487428a09371878a111d8d5138a97252ea040b15c968cd9efb22aa72ab
git-daemon-2.18.2-2.el8_0.ppc64le.rpm SHA-256: 77002db1287cd1626b64d194840cf76a13bafeb0d57203abac4d114fba096c5e
git-daemon-debuginfo-2.18.2-2.el8_0.ppc64le.rpm SHA-256: 497533aa64616d7c273e4d22f5aea09598daf807793ad9eb1c3375a3c2725c89
git-debuginfo-2.18.2-2.el8_0.ppc64le.rpm SHA-256: b017d6561da0f6fe8f050e663ed0fd04c5372bc01fb9ef71a5697d615cfcfbe8
git-debugsource-2.18.2-2.el8_0.ppc64le.rpm SHA-256: 88c116f80af827bfb13566f340a4d8c22945675e4cb2dbf63bd9ecd07775f3b9
git-email-2.18.2-2.el8_0.noarch.rpm SHA-256: 13cd064ee002b0e4662538ee0a7b50e226450dae1efe610753f191874812fe80
git-gui-2.18.2-2.el8_0.noarch.rpm SHA-256: 3c866b2f13ca2d35463ff07037a08b94ad15700643d0bdcddb681daf20a0a2c8
git-instaweb-2.18.2-2.el8_0.ppc64le.rpm SHA-256: 0c3c749cb33c911972d49922a7ec39dbb77c070526aa884f81092bfc04c397eb
git-subtree-2.18.2-2.el8_0.ppc64le.rpm SHA-256: 4b7472b183439a80d5879a5e7da563034aa387197d1b3ca4d154c8054b339436
git-svn-2.18.2-2.el8_0.ppc64le.rpm SHA-256: f6076bd9fde24ffaf639e93589dd1111b6f87fe583cd9dd201f2e0ea72f2c0ce
git-svn-debuginfo-2.18.2-2.el8_0.ppc64le.rpm SHA-256: da0f3060f1c42329d61c5c9f66ccd165d18d417d378223a2d91a360aa8502a42
gitk-2.18.2-2.el8_0.noarch.rpm SHA-256: fede1c15afe6728faa30d92e272d311d129e8c109bfc12d8e27fbf56e1c33e9c
gitweb-2.18.2-2.el8_0.noarch.rpm SHA-256: b34b3e1a30721e6c14c44e9dd53cda2b813d3c58fe299d04ca7782d3f4a04c45
perl-Git-2.18.2-2.el8_0.noarch.rpm SHA-256: 232dd4220ee20afd41cd5414b54e511e1b7be96113e9a55913156f7754ead8ec
perl-Git-SVN-2.18.2-2.el8_0.noarch.rpm SHA-256: d1d08cdcf1a876b98572e962c9ab94d95f3dce68c8f26e960e485d5adcb9c5d7

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.0

SRPM
git-2.18.2-2.el8_0.src.rpm SHA-256: 4219c298d36011f6eac81c6c9f0fdaa06b2b8bea5446f8a9e7a3469f1515b392
x86_64
git-2.18.2-2.el8_0.x86_64.rpm SHA-256: 0f4a06e8a37857cbb2062ff21901dac1c759417eeac37e89e6685e09af4a216c
git-all-2.18.2-2.el8_0.noarch.rpm SHA-256: 869070b1000b681e55f09a0b922d3f411fd209a0418b1f81bf122fbcff444215
git-core-2.18.2-2.el8_0.x86_64.rpm SHA-256: b6c40f4f1fcdcb152eb67e2e2f750eb21bb660c2015bf27bc2beab464e4d0b85
git-core-debuginfo-2.18.2-2.el8_0.x86_64.rpm SHA-256: 0379c6c07914d8db1178602f7177b210f3c8e4e6cc3ca5df47867729823062e4
git-core-doc-2.18.2-2.el8_0.noarch.rpm SHA-256: c22d43487428a09371878a111d8d5138a97252ea040b15c968cd9efb22aa72ab
git-daemon-2.18.2-2.el8_0.x86_64.rpm SHA-256: c95ea28830eb1ce19c85ff6c9f78b106bced4a9d1b76cdb1881e72c924c0b722
git-daemon-debuginfo-2.18.2-2.el8_0.x86_64.rpm SHA-256: 207e439bebb4a3de5207385d09a0c2a3d0e6404842f80c35a40e0f157ed44581
git-debuginfo-2.18.2-2.el8_0.x86_64.rpm SHA-256: 4491b42de070c9a9ded731afcdc10bbe31d9c2b7427934cb4c4e97dac7d9fca6
git-debugsource-2.18.2-2.el8_0.x86_64.rpm SHA-256: d36161477438d63e0276ccf4e31b587f3d982869b879016e7baca45a46650273
git-email-2.18.2-2.el8_0.noarch.rpm SHA-256: 13cd064ee002b0e4662538ee0a7b50e226450dae1efe610753f191874812fe80
git-gui-2.18.2-2.el8_0.noarch.rpm SHA-256: 3c866b2f13ca2d35463ff07037a08b94ad15700643d0bdcddb681daf20a0a2c8
git-instaweb-2.18.2-2.el8_0.x86_64.rpm SHA-256: 1b93f9238a7a5aea02f226506b906914b65fb34c5297343ec428f885083ede1f
git-subtree-2.18.2-2.el8_0.x86_64.rpm SHA-256: b33f3e2a6ba781ac8a52a0aeb29a868319fc914cd72812cd156ff06fe1777440
git-svn-2.18.2-2.el8_0.x86_64.rpm SHA-256: bf3b4434e94fe0d337bb786be6bb776a977d0cbdd321f8d6c62b2f0d495ab387
git-svn-debuginfo-2.18.2-2.el8_0.x86_64.rpm SHA-256: 11a603db36a401c962ea8e6657a49b7c96acd8956bf50d222cc98e2c21472955
gitk-2.18.2-2.el8_0.noarch.rpm SHA-256: fede1c15afe6728faa30d92e272d311d129e8c109bfc12d8e27fbf56e1c33e9c
gitweb-2.18.2-2.el8_0.noarch.rpm SHA-256: b34b3e1a30721e6c14c44e9dd53cda2b813d3c58fe299d04ca7782d3f4a04c45
perl-Git-2.18.2-2.el8_0.noarch.rpm SHA-256: 232dd4220ee20afd41cd5414b54e511e1b7be96113e9a55913156f7754ead8ec
perl-Git-SVN-2.18.2-2.el8_0.noarch.rpm SHA-256: d1d08cdcf1a876b98572e962c9ab94d95f3dce68c8f26e960e485d5adcb9c5d7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility