Description of the LOTP tool
git is often present in CI pipelines where repos are pulled in at build time. Being able to control GIT_SSH or GIT_SSH_COMMAND in the pipeline environment variables could result in code execution on build hosts where direct access to the host isn't possible.
Ref
Description of the LOTP tool
gitis often present in CI pipelines where repos are pulled in at build time. Being able to controlGIT_SSHorGIT_SSH_COMMANDin the pipeline environment variables could result in code execution on build hosts where direct access to the host isn't possible.Ref