Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2020-28086

7.5 · HIGH
Published Dec 9, 2020 zx2c4 CWE-347 EPSS 0.59% (46th pctl)

Overview

CVE-2020-28086 is a high-severity vulnerability affecting zx2c4 password-store. It was published on December 9, 2020 and has a CVSS 3.1 base score of 7.5 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an attacker controls the central Git server or one of the other members' machines, and also controls one of the services already in the password store, they can rename one of the password files in the Git repository to something else: pass doesn't correctly verify that the content of a file matches the filename, so a user might be tricked into decrypting the wrong password and sending that to a service that the attacker controls. NOTE: for environments in which this threat model is of concern, signing commits can be a solution.

Remediation

Check the references section for vendor advisories and patches from zx2c4. Update password-store to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
zx2c4 password-store 0 Affected

Frequently Asked Questions

What is CVE-2020-28086?

CVE-2020-28086 is a high-severity vulnerability affecting zx2c4 password-store. It was published on December 9, 2020 and has a CVSS 3.1 base score of 7.5 (HIGH).

How severe is CVE-2020-28086?

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2020-28086?

Check the references section for vendor advisories and patches from zx2c4. Update password-store to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2020-28086?

CyberStrike's AI-powered security agents can automatically detect CVE-2020-28086 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.