CVE-2013-0308: Git-Scm Git
Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.
The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected products
- Git-Scm Git: up to and including 1.8.1.3
Published 2013-03-08. Last modified 2026-06-16.