)]}'
{
  "commit": "08756131a3b7038a60365ae56804cea4301082a9",
  "tree": "1b1ef503233ddfcb23686e0cd415f008bf35631a",
  "parents": [
    "062d9fb033ec994305343bb28dbad3c2f799de47",
    "b01b9b81d36759cdcd07305e78765199e1bc2060"
  ],
  "author": {
    "name": "Johannes Schindelin",
    "email": "johannes.schindelin@gmx.de",
    "time": "Tue Oct 29 23:52:11 2024 +0100"
  },
  "committer": {
    "name": "Johannes Schindelin",
    "email": "johannes.schindelin@gmx.de",
    "time": "Tue Nov 26 22:14:45 2024 +0100"
  },
  "message": "Merge branch \u0027disallow-control-characters-in-credential-urls-by-default\u0027\n\nThis addresses two vulnerabilities:\n\n- CVE-2024-50349:\n\n\tPrinting unsanitized URLs when asking for credentials made the\n\tuser susceptible to crafted URLs (e.g. in recursive clones) that\n\tmislead the user into typing in passwords for trusted sites that\n\twould then be sent to untrusted sites instead.\n\n- CVE-2024-52006\n\n\tGit may pass on Carriage Returns via the credential protocol to\n\tcredential helpers which use line-reading functions that\n\tinterpret said Carriage Returns as line endings, even though Git\n\tdid not intend that.\n\nSigned-off-by: Johannes Schindelin \u003cjohannes.schindelin@gmx.de\u003e\n",
  "tree_diff": []
}
