| ▲ | saghm a day ago | |
> When babeld forwards a push request, one of the internal requests includes push options in the X-Stat header. Git push options are arbitrary strings that users can pass with git push -o. They are a standard git protocol feature, intended for server-side hints. babeld encodes them as numbered fields - push_option_0, push_option_1, and so on - alongside a push_option_count. > babeld copies git push option values directly into the X-Stat header - without sanitizing semicolons. Since ; is the X-Stat field delimiter, any semicolon in a push option value breaks out of its designated field and creates new, attacker-controlled fields. They managed to literally do the simplest possible thing wrong. The fruit was hanging so low it might have been underground. | ||
| ▲ | irishcoffee a day ago | parent [-] | |
Oh Bobby Tables, your mom was quite clever. | ||