Описание
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.
Ссылки
- Patch
- ProductRelease Notes
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.6.0 (включая) до 0.11.6 (исключая)
cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*
EPSS
Процентиль: 30%
0.00364
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200
Связанные уязвимости
github
5 месяцев назад
In Soft Serve, an authenticated repo import can clone server-local private repositories
EPSS
Процентиль: 30%
0.00364
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200