Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:1978 - Security Advisory
Issued:
2020-04-30
Updated:
2020-04-30

RHSA-2020:1978 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: git security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for git is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.

The following packages have been upgraded to a later upstream version: git (2.18.4). (BZ#1826006)

Security Fix(es):

  • git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak (CVE-2020-11008)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.0 x86_64

Fixes

  • BZ - 1826001 - CVE-2020-11008 git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak

CVEs

  • CVE-2020-11008

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.0

SRPM
git-2.18.4-1.el8_0.src.rpm SHA-256: b81e3b6fc4dfadd6a24cc73304b0022ca90e136fd05ac822e55b6dd5aae5946e
ppc64le
git-2.18.4-1.el8_0.ppc64le.rpm SHA-256: eda226fdba1f0e5aecbff632c12f2774f4df1c0c1d01488aff5494b87babe207
git-all-2.18.4-1.el8_0.noarch.rpm SHA-256: b423c8bb01c156bf526587409eaebaddb42c908e23b7df82552d028aeb379281
git-core-2.18.4-1.el8_0.ppc64le.rpm SHA-256: 99fc10fe8b5bc9fb4d95f5c9416423dac95f396a6b171919e1291dec808a766f
git-core-debuginfo-2.18.4-1.el8_0.ppc64le.rpm SHA-256: 2c14635ddbd86304b033ad5295fcf9c1291631d371a56c3331d1c53361b6f5c0
git-core-doc-2.18.4-1.el8_0.noarch.rpm SHA-256: d1b13d4d77a360ea3ede10fa562e62a30361a82518245f591ac7c2cb91887a8a
git-daemon-2.18.4-1.el8_0.ppc64le.rpm SHA-256: 8fbf1c9dcb9275b839577f85caa6fa38c5f58176f52022686dac515f788c33f6
git-daemon-debuginfo-2.18.4-1.el8_0.ppc64le.rpm SHA-256: 5d29e1f8222be08c42294e94d7f9c190eb049d5ee29a5c2e924ab7f7c01ec50a
git-debuginfo-2.18.4-1.el8_0.ppc64le.rpm SHA-256: b0d4766f5fef83421edade7e425b4e2d71cedd117f9a4ece3dc2e5e508744fb4
git-debugsource-2.18.4-1.el8_0.ppc64le.rpm SHA-256: a34a29fa22d4d605f2df7da434d7e940f25a98cd7e15a470a5cec51a1747fc7b
git-email-2.18.4-1.el8_0.noarch.rpm SHA-256: 486398ff658a7ac0b81578af89b050ddcbe5e9731267954a40c2663fffc8767e
git-gui-2.18.4-1.el8_0.noarch.rpm SHA-256: a48d1de368a545311f83bd22b9074634e4d5e78b68e667a6f2237776dec8192d
git-instaweb-2.18.4-1.el8_0.ppc64le.rpm SHA-256: 5ca10d6480bd9c7e37059fa7627708fb687d5af2508340632874c09785d23f5d
git-subtree-2.18.4-1.el8_0.ppc64le.rpm SHA-256: 7666018e657901fea8c2b53e60937737bc61d5bc42260d1d1ba0487ed0c999b2
git-svn-2.18.4-1.el8_0.ppc64le.rpm SHA-256: 6209970a395868c69ca67ba77368dd695bc6112facd48afd0a1a78667191bfa7
git-svn-debuginfo-2.18.4-1.el8_0.ppc64le.rpm SHA-256: 994d5fb9b1b2f1a76bbb82018ce77ccba314de76b2b0c291c4a90cb5ac824362
gitk-2.18.4-1.el8_0.noarch.rpm SHA-256: 95a47b04bbe1d97e16b0d98124f4d078892c25c435b921e9a0c344a39275a386
gitweb-2.18.4-1.el8_0.noarch.rpm SHA-256: 77c400cffcc5ef1553312e2ea8a83da73e18b45fe176d6b9a5b8e2b672d7b031
perl-Git-2.18.4-1.el8_0.noarch.rpm SHA-256: 81a2c337adaf34e2d1e84516ab4fdead6a7cb8d812e581dd3730e2053212e9c7
perl-Git-SVN-2.18.4-1.el8_0.noarch.rpm SHA-256: f07e15adf8cb3edb7747282da86d1dd69b19e60f6bc386103617f41a8e5fd719

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.0

SRPM
git-2.18.4-1.el8_0.src.rpm SHA-256: b81e3b6fc4dfadd6a24cc73304b0022ca90e136fd05ac822e55b6dd5aae5946e
x86_64
git-2.18.4-1.el8_0.x86_64.rpm SHA-256: bb083db0d3efc16dfd52db8afc2e1523c70d19effce72c577609c719b2ecd079
git-all-2.18.4-1.el8_0.noarch.rpm SHA-256: b423c8bb01c156bf526587409eaebaddb42c908e23b7df82552d028aeb379281
git-core-2.18.4-1.el8_0.x86_64.rpm SHA-256: 00c573a7473ac2281dc0b9b596042e7c84971677d64535d3f30c1eb4012edec6
git-core-debuginfo-2.18.4-1.el8_0.x86_64.rpm SHA-256: 71ca064f8bdcc415bf4f3f5f4c020ef3724612f182ab813a9111788e4fb0640a
git-core-doc-2.18.4-1.el8_0.noarch.rpm SHA-256: d1b13d4d77a360ea3ede10fa562e62a30361a82518245f591ac7c2cb91887a8a
git-daemon-2.18.4-1.el8_0.x86_64.rpm SHA-256: c481895dd521f66227b5742838c0137b7ef1e0800b863e0503147b779032a4c1
git-daemon-debuginfo-2.18.4-1.el8_0.x86_64.rpm SHA-256: 7967b54ca17c13a0832a5fe9512a01c8803039b2d0ed2efbdeebd5ece2a60e05
git-debuginfo-2.18.4-1.el8_0.x86_64.rpm SHA-256: ab95c5f781e4b2acef2a11cbe86a659862b917dd47a34caef0e08beef6d1a54a
git-debugsource-2.18.4-1.el8_0.x86_64.rpm SHA-256: 8b4a52fc1ec298c7335d0804449648c6012de54623c6aee28507c1cb61dd61d8
git-email-2.18.4-1.el8_0.noarch.rpm SHA-256: 486398ff658a7ac0b81578af89b050ddcbe5e9731267954a40c2663fffc8767e
git-gui-2.18.4-1.el8_0.noarch.rpm SHA-256: a48d1de368a545311f83bd22b9074634e4d5e78b68e667a6f2237776dec8192d
git-instaweb-2.18.4-1.el8_0.x86_64.rpm SHA-256: 3d0cb34d6fbd899ef310b30a349532cfaf1d9c20332f3cef67b215191d280613
git-subtree-2.18.4-1.el8_0.x86_64.rpm SHA-256: ec19fe16a7aca522e52dc2f10ae161edd37fe9523eaada1d22e1418d2353766d
git-svn-2.18.4-1.el8_0.x86_64.rpm SHA-256: 98537f1ff3818bb463f116f81181ff054a13e0c7c8ef8549493f4ac13aa55628
git-svn-debuginfo-2.18.4-1.el8_0.x86_64.rpm SHA-256: fecd54c6d0306b30d101c37515f77bd7a8729483b9434b309cd53bb4d79876f9
gitk-2.18.4-1.el8_0.noarch.rpm SHA-256: 95a47b04bbe1d97e16b0d98124f4d078892c25c435b921e9a0c344a39275a386
gitweb-2.18.4-1.el8_0.noarch.rpm SHA-256: 77c400cffcc5ef1553312e2ea8a83da73e18b45fe176d6b9a5b8e2b672d7b031
perl-Git-2.18.4-1.el8_0.noarch.rpm SHA-256: 81a2c337adaf34e2d1e84516ab4fdead6a7cb8d812e581dd3730e2053212e9c7
perl-Git-SVN-2.18.4-1.el8_0.noarch.rpm SHA-256: f07e15adf8cb3edb7747282da86d1dd69b19e60f6bc386103617f41a8e5fd719

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility