Описание
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.
Уязвимые конфигурации
Конфигурация 1Версия до 0.8.2 (исключая)
cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*
EPSS
Процентиль: 71%
0.00683
Низкий
8.8 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 71%
0.00683
Низкий
8.8 High
CVSS3
Дефекты
CWE-22