CVE-2014-6274
published 2025-06-26CVE-2014-6274: git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the embedded AWS…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.15%
5.1th percentile
git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes
was set, and the remote used encryption=pubkey or encryption=hybrid,
the embedded AWS credentials were stored in the git repository
in (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from 3.20121126 before 5.20140919.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | git-annex | < git-annex 5.20140919 (bookworm) | git-annex 5.20140919 (bookworm) |
| git-annex | git-annex | >= 3.20121126 < 5.20140919 | 5.20140919 |
| git-annex_project | git-annex | >= 0 < 5.20140919 | 5.20140919 |
| git-annex_project | git-annex | >= 0 < 5.20140919 | 5.20140919 |
| git-annex_project | git-annex | >= 0 < 5.20140919 | 5.20140919 |
| git-annex_project | git-annex | >= 0 < 5.20140919 | 5.20140919 |
| git-annex_project | git-annex | >= 0.20110401 < 5.20140919 | 5.20140919 |
| git-annex_project | git-annex | >= 3.20121126 < 5.20140919 | 5.20140919 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
git-annex plaintext storage of embedded credentials on encrypted remotes
osv·2025-11-14
CVE-2014-6274 git-annex plaintext storage of embedded credentials on encrypted remotes
git-annex plaintext storage of embedded credentials on encrypted remotes
# *git-annex* plaintext storage of embedded credentials on encrypted remotes
*git-annex* had a bug in the **S3** and **Glacier** remotes where if
`embedcreds=yes` was set, and the remote used `encryption=pubkey` or
`encryption=hybrid`, the embedded AWS credentials were stored in the
Git repository in (effectively) plaintext, not encrypted as they
were supposed to be.
That means that anyone who gets a copy of the Git repository can
extract the AWS credentials from it. Which would be bad.
A remote with this problem cannot be enabled using `git annex
enableremote`. Old versions of *git-annex* will fail with a GPG
error; the current version will fail with a pointer to this web
page.
## Remediation
If your repository
GHSA
GHSA-ppj6-rmfj-4vjx: git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes
was set, and the remote used encryption=pubkey or encryption=hybrid,
the emb
ghsa_unreviewed·2025-06-26
CVE-2014-6274 [HIGH] CWE-311 GHSA-ppj6-rmfj-4vjx: git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes
was set, and the remote used encryption=pubkey or encryption=hybrid,
the emb
git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes
was set, and the remote used encryption=pubkey or encryption=hybrid,
the embedded AWS credentials were stored in the git repository
in (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from 3.20121126 before 5.20140919.
OSV
CVE-2014-6274: git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the emb
osv·2025-06-26·CVSS 7.5
CVE-2014-6274 [HIGH] CVE-2014-6274: git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the emb
git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the embedded AWS credentials were stored in the git repository in (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from 3.20121126 before 5.20140919.
Debian
CVE-2014-6274: git-annex - git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was se...
vendor_debian·2014·CVSS 7.5
CVE-2014-6274 [HIGH] CVE-2014-6274: git-annex - git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was se...
git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the embedded AWS credentials were stored in the git repository in (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from 3.20121126 before 5.20140919.
Scope: local
bookworm: resolved (fixed in 5.20140919)
bullseye: resolved (fixed in 5.20140919)
forky: resolved (fixed in 5.20140919)
sid: resolved (fixed in 5.20140919)
trixie: resolved (fixed in 5.20140919)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-26
Published