Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhj8-pmrq-xphp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists function.

git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists function.

EPSS

Процентиль: 77%
0.01027
Низкий

Дефекты

CWE-77

Связанные уязвимости

nvd
около 11 лет назад

git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists function.

EPSS

Процентиль: 77%
0.01027
Низкий

Дефекты

CWE-77