Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-47515

Опубликовано: 24 дек. 2024
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pagurefixed5.14.1+dfsg-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2315806

  • Fixed by: https://pagure.io/pagure/c/9b715170008bdc1dd273f7c28debe782a8f7969e (5.14.1)

EPSS

Процентиль: 45%
0.00225
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 года назад

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.

CVSS3: 8.1
nvd
около 1 года назад

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.

CVSS3: 8.1
github
около 1 года назад

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.

EPSS

Процентиль: 45%
0.00225
Низкий