---
title: "CVE-2020-28086\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-28086?format=md
keywords: index, follow
---

# CVE-2020-28086

Publication date 9 December 2020

Last updated 11 July 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2020-28086?format=md#impact-score)

Toggle side navigation

## Description

pass through 1.7.3 has a possibility of using a password for an unintended
resource. For exploitation to occur, the user must do a git pull, decrypt a
password, and log into a remote service with the password. If an attacker
controls the central Git server or one of the other members' machines, and
also controls one of the services already in the password store, they can
rename one of the password files in the Git repository to something else:
pass doesn't correctly verify that the content of a file matches the
filename, so a user might be tricked into decrypting the wrong password and
sending that to a service that the attacker controls. NOTE: for
environments in which this threat model is of concern, signing commits can
be a solution.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| password-store | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 23.10 mantic | Ignored end of life, was needs-triage |
| 23.04 lunar | Ignored end of life, was needs-triage |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Needs evaluation |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | High |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28086)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-28086)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-28086)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-28086)

### Other references

* <https://lists.zx2c4.com/pipermail/password-store/2014-March/000498.html>
* <https://www.cve.org/CVERecord?id=CVE-2020-28086>
