Skip to content
Snippets Groups Projects

Trust file-content-metadata path on CVMFS when cloning

Merged Chris Burr requested to merge cburr/git-2.45.1-plus into master
All threads resolved!

To mitigate the vulnerability CVE-2024-32004, when cloning from a local repository, the directory have to be owned by the user doing the cloning or explicitly trusted. This change temporarily trusts the file-content-metadata repository in CVMFS before cloning it, if needed.

See: https://lore.kernel.org/git/20240529102307.GF1098944@coredump.intra.peff.net/T/#t

Replaces !4585 (closed)

Edited by Chris Burr

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
Please register or sign in to reply
Loading