{"id":"CVE-2014-6274","details":"git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes\nwas set, and the remote used encryption=pubkey or encryption=hybrid,\nthe embedded AWS credentials were stored in the git repository\nin (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from 3.20121126 before 5.20140919.","aliases":["HSEC-2023-0013"],"modified":"2026-04-10T03:43:58.533173Z","published":"2025-06-26T21:15:27Z","references":[{"type":"WEB","url":"https://git-annex.branchable.com/upgrades/insecure_embedded_creds/"}],"schema_version":"1.7.5"}