Malicious URLs cause Git (v2.26.0) to present stored credentials to wrong server
1–3 of 3 posts
Re: Malicious URLs cause Git (v2.26.0) to present stored credentials to wrong server
#2Without upgrade, this might be exploited through package managers able to fetch from Git URLs (so NPM, Go Modules, and others).
Re: Malicious URLs cause Git (v2.26.0) to present stored credentials to wrong server
#3Xcode 11.4.1 came out today and it appears to contain the fix for this.