git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes
was set, and the remote used encryption=pubkey or encryption=hybrid,
the embedded AWS credentials were stored in the git repository
in (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from 3.20121126 before 5.20140919.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Aug 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Git-annex Project
Git-annex Project git-annex |
|
CPEs | cpe:2.3:a:git-annex_project:git-annex:*:*:*:*:*:*:*:* | |
Vendors & Products |
Git-annex Project
Git-annex Project git-annex |
Fri, 27 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-311 | |
Metrics |
cvssV3_1
|
Thu, 26 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the embedded AWS credentials were stored in the git repository in (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from 3.20121126 before 5.20140919. | |
Title | S3 and Glacier remotes creds embedded in the git repo were not encrypted | |
References |
|

Status: PUBLISHED
Assigner: debian
Published: 2025-06-26T20:59:54.999Z
Updated: 2025-06-27T18:41:32.782Z
Reserved: 2014-09-09T00:00:00.000Z
Link: CVE-2014-6274

Updated: 2025-06-27T18:41:16.692Z

Status : Analyzed
Published: 2025-06-26T21:15:27.647
Modified: 2025-08-06T16:36:19.350
Link: CVE-2014-6274

No data.