Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
git-vuln-finder — Git 커밋 메시지에서 잠재적인 소프트웨어 취약점 찾기 | Kitploit
도구/GitHubGitHub/cve-search/git-vuln-finder
OSINT (Open Source Intelligence)Vulnerability AnalysisCode Analysis
GitHubcve-search/git-vuln-finder

git-vuln-finder

Git 커밋 메시지에서 잠재적인 소프트웨어 취약점 찾기

저장소 보기웹사이트
4265892년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

git-vuln-finder

git-vuln-finder 로고

Workflow

git 커밋 메시지에서 잠재적인 소프트웨어 취약점을 찾습니다. 출력 형식은 소프트웨어 취약점에 대한 수정 사항이 포함될 수 있는 관련 커밋이 있는 JSON입니다. 검색은 커밋 메시지에 대한 정규식 집합을 기반으로 합니다. CVE ID가 있는 경우 출력에 자동으로 추가됩니다. 입력은 모든 git 리포지토리 또는 GH 아카이브 소스일 수 있습니다.

요구 사항

  • jq (sudo apt install jq)
  • Python poetry

설치

라이브러리로 사용

git-vuln-finder는 poetry로 설치할 수 있습니다. poetry가 설치되어 있지 않다면 curl -sSL https://raw.githubusercontent.com/python-poetry/poetry/master/get-poetry.py | python을 실행할 수 있습니다.

$ poetry install
$ poetry shell
$ git-vuln-finder -h

pip을 사용할 수도 있습니다. 그런 다음 임포트하십시오:

Python 3.8.0 (default, Dec 11 2019, 21:43:13)
[GCC 9.2.1 20191008] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> from git_vuln_finder import find
>>> all_potential_vulnerabilities, all_cve_found, found = find("~/git/curl")

>>> [commit for commit, summary in all_potential_vulnerabilities.items() if summary['state'] == 'cve-assigned']
['9069838b30fb3b48af0123e39f664cea683254a5', 'facb0e4662415b5f28163e853dc6742ac5fafb3d',
... snap ...
 '8a75dbeb2305297640453029b7905ef51b87e8dd', '1dc43de0dccc2ea7da6dddb7b98f8d7dcf323914', '192c4f788d48f82c03e9cef40013f34370e90737', '2eb8dcf26cb37f09cffe26909a646e702dbcab66', 'fa1ae0abcde5df8d0b3283299e3f246bedf7692c', 'c11c30a8c8d727dcf5634fa0cc6ee0b4b77ddc3d', '75ca568fa1c19de4c5358fed246686de8467c238', 'a20daf90e358c1476a325ea665d533f7a27e3364', '042cc1f69ec0878f542667cb684378869f859911']

 >>> print(json.dumps(all_potential_vulnerabilities['9069838b30fb3b48af0123e39f664cea683254a5'], sort_keys=True, indent=4, separators=(",", ": ")))
 {
     "author": "Daniel Stenberg",
     "author-email": "[email protected]",
     "authored_date": 1567544372,
     "branches": [
         "master"
     ],
     "commit-id": "9069838b30fb3b48af0123e39f664cea683254a5",
     "committed_date": 1568009674,
     "cve": [
         "CVE-2019-5481",
         "CVE-2019-5481"
     ],
     "language": "en",
     "message": "security:read_data fix bad realloc()\n\n... that could end up a double-free\n\nCVE-2019-5481\nBug: https://curl.haxx.se/docs/CVE-2019-5481.html\n",
     "origin": "https://github.com/curl/curl.git",
     "origin-github-api": "https://api.github.com/repos///github.com/curl/curl/commits/9069838b30fb3b48af0123e39f664cea683254a5",
     "pattern-matches": [
         "double-free"
     ],
     "pattern-selected": "(?i)(double[-| ]free|buffer overflow|double free|race[-| ]condition)",
     "state": "cve-assigned",
     "stats": {
         "deletions": 4,
         "files": 1,
         "insertions": 2,
         "lines": 6
     },
     "summary": "security:read_data fix bad realloc()",
     "tags": []
 }

명령줄 도구로 사용

$ git clone https://github.com/cve-search/git-vuln-finder.git
$ cd https://github.com/cve-search/git-vuln-finder.git
$ pip install .
$ git-vuln-finder --help

pip을 사용할 수도 있습니다. pipx는 Python 패키지에서 제공하는 스크립트(시스템 전체에서 사용 가능)를 별도의 가상 환경에 설치하여 시스템 및 서로로부터 보호합니다.

사용법

usage: git-vuln-finder [-h] [-v] [-r R] [-o O] [-s S] [-p P] [-c] [-t] [-gh GH]

git 커밋 메시지에서 잠재적인 소프트웨어 취약점을 찾습니다.

선택적 인수:
  -h, --help  이 도움말 메시지를 표시하고 종료합니다.
  -v          출력 상세도를 높입니다.
  -r R        분석할 git 리포지토리
  -o O        출력 형식: [json]
  -s S        발견된 커밋의 상태
  -p P        사용할 매칭 패턴: [vulnpatterns, cryptopatterns, cpatterns] - 패턴 'all'은 모든 패턴을 한 번에 매칭하는 데 사용됩니다.
  -c          커밋 메시지에서 발견된 CVE 패턴 목록만 출력합니다(기본적으로 비활성화됨).
  -t          특정 커밋과 일치하는 태그 포함
  -gh GH      gharchive용 특수 옵션, PushEvent를 JSON 형식으로 포함하는 파일 전달

자세한 정보: https://github.com/cve-search/git-vuln-finder

패턴

git-vuln-finder는 3개의 기본 패턴과 함께 제공되며, 이를 선택하여 커밋 메시지에 설명된 잠재적 취약점을 찾을 수 있습니다:

  • vulnpatterns는 웹 애플리케이션 및 일반 보안 커밋 메시지를 특히 대상으로 하는 일반적인 취약점 패턴입니다. 학술 논문을 기반으로 합니다.
  • cryptopatterns는 커밋 메시지에 언급된 암호화 오류에 대한 취약점 패턴입니다.
  • cpatterns는 C/C++ 계열 언어에서 볼 수 있는 표준 취약점 패턴 집합입니다.

Curl git 리포지토리의 샘플 부분 출력

$ git-vuln-finder -r ~/git/curl | jq .
...
 "6df916d751e72fc9a1febc07bb59c4ddd886c043": {
    "message": "loadlibrary: Only load system DLLs from the system directory\n\nInspiration provided by: Daniel Stenberg and Ray Satiro\n\nBug: https://curl.haxx.se/docs/adv_20160530.html\n\nRef: Windows DLL hijacking with curl, CVE-2016-4802\n",
    "language": "en",
    "commit-id": "6df916d751e72fc9a1febc07bb59c4ddd886c043",
    "summary": "loadlibrary: Only load system DLLs from the system directory",
    "stats": {
      "insertions": 180,
      "deletions": 8,
      "lines": 188,
      "files": 7
    },
    "author": "Steve Holme",
    "author-email": "[email protected]",
    "authored_date": 1464555460,
    "committed_date": 1464588867,
    "branches": [
      "master"
    ],
    "pattern-selected": "(?i)(denial of service |\bXXE\b|remote code execution|\bopen redirect|OSVDB|\bvuln|\bCVE\b |\bXSS\b|\bReDoS\b|\bNVD\b|malicious|x−frame−options|attack|cross site |exploit|malicious|directory traversal |\bRCE\b|\bdos\b|\bXSRF \b|\bXSS\b|clickjack|session.fixation|hijack|\badvisory|\binsecure |security |\bcross−origin\b|unauthori[z|s]ed |infinite loop)",
    "pattern-matches": [
      "hijack"
    ],
    "origin": "[email protected]:curl/curl.git",
    "origin-github-api": "https://api.github.com/repos/curl/curl/commits/6df916d751e72fc9a1febc07bb59c4ddd886c043",
    "tags": [],
    "cve": [
      "CVE-2016-4802"
    ],
    "state": "cve-assigned"
  },
  "c2b3f264cb5210f82bdc84a3b89250a611b68dd3": {
    "message": "CONNECT_ONLY: don't close connection on GSS 401/407 reponses\n\nPreviously, connections were closed immediately before the user had a\nchance to extract the socket when the proxy required Negotiate\nauthentication.\n\nThis regression was brought in with the security fix in commit\n79b9d5f1a42578f\n\nCloses #655\n",
    "language": "en",
    "commit-id": "c2b3f264cb5210f82bdc84a3b89250a611b68dd3",
    "summary": "CONNECT_ONLY: don't close connection on GSS 401/407 reponses",
    "stats": {
      "insertions": 4,
      "deletions": 2,
      "lines": 6,
      "files": 1
    },
    "author": "Marcel Raad",
    "author-email": "[email protected]",
    "authored_date": 1455523116,
    "committed_date": 1461704516,
    "branches": [
      "master"
    ],
    "pattern-selected": "(?i)(denial of service |\bXXE\b|remote code execution|\bopen redirect|OSVDB|\bvuln|\bCVE\b |\bXSS\b|\bReDoS\b|\bNVD\b|malicious|x−frame−options|attack|cross site |exploit|malicious|directory traversal |\bRCE\b|\bdos\b|\bXSRF \b|\bXSS\b|clickjack|session.fixation|hijack|\badvisory|\binsecure |security |\bcross−origin\b|unauthori[z|s]ed |infinite loop)",
    "pattern-matches": [
      "security "
    ],
    "origin": "[email protected]:curl/curl.git",
    "origin-github-api": "https://api.github.com/repos/curl/curl/commits/c2b3f264cb5210f82bdc84a3b89250a611b68dd3",
    "tags": [],
    "state": "under-review"
  },
...
  • git 메시지에서 CVE ID 추출
도구 다운로드