
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-12278 is a security vulnerability discovered in libgit2 versions before 0.28.4 and 0.9x before 0.99.0. The vulnerability was disclosed in April 2020 and affects the path.c component of libgit2, which mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This vulnerability could potentially allow remote code execution when cloning a repository (NVD, Ubuntu Security).
The vulnerability stems from the way path.c handles NTFS Alternate Data Streams. The issue is similar to CVE-2019-1352 and affects the path handling mechanism when dealing with equivalent filenames on NTFS filesystems. The vulnerability has been assigned a CVSS v3.1 Base Score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a critical severity level with network attack vector, low attack complexity, and no required privileges or user interaction (NVD).
The vulnerability could allow an attacker to execute remote code when a repository is cloned. This is particularly concerning as it affects not only Windows systems but also other platforms that interact with NTFS filesystems, including systems accessing NTFS through mounted network shares (Debian Security).
The vulnerability can be exploited when cloning a repository on systems that use or interact with NTFS filesystems. The attack vector involves manipulating filenames using NTFS Alternate Data Streams, which could lead to arbitrary code execution (Ubuntu Security).
The vulnerability has been patched in libgit2 version 0.28.4 and 0.99.0. The fix involves implementing proper validation of paths and rejecting any paths that use NTFS Alternate Data Streams. Users are recommended to upgrade to these or later versions. The patches include commits 3f7851e and e1832eb which specifically address the NTFS Alternate Data Stream attacks (Git Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."