Описание
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
Ссылки
- Vendor Advisory
- Permissions Required
- ExploitIssue TrackingVendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1Версия до 5.14.1 (исключая)
cpe:2.3:a:redhat:pagure:*:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.00107
Низкий
7.6 High
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.6
ubuntu
9 месяцев назад
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
CVSS3: 7.6
debian
9 месяцев назад
A directory traversal vulnerability was discovered in Pagure server. I ...
CVSS3: 7.6
github
9 месяцев назад
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
EPSS
Процентиль: 30%
0.00107
Низкий
7.6 High
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-22