Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4jw-m6xr-fv6c

Опубликовано: 08 янв. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Soft Serve vulnerable to path traversal attacks

Impact

Path traversal attack gives access to existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions.

Patches

This is patched in v0.8.2

Workarounds

Single user set-ups are not affected. This only affects multi-user Soft Serve set-ups that enable repository creation for users. Otherwise, upgrading is necessary to circumvent the attack.

Пакеты

Наименование

github.com/charmbracelet/soft-serve

go
Затронутые версииВерсия исправления

< 0.8.2

0.8.2

EPSS

Процентиль: 71%
0.00683
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.

suse-cvrf
около 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 71%
0.00683
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-22