Описание
Security update for cgit
This update for cgit fixes the following issues:
The following security vulnerability was addressed:
- CVE-2018-14912: Fixed a directory traversal vulnerability, when enable-http-clone=1 is not turned off (boo#1103799)
The following other changes were made:
- Update to upstream release 1.2.1
- syntax-highlighting: replace invalid unicode with '?'
- ui-repolist: properly sort by age
- ui-patch: fix crash when using path limit
Список пакетов
openSUSE Leap 15.0
cgit-1.2.1-lp150.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2018:2308-1
- SUSE Security Ratings
Описание
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.
Затронутые продукты
openSUSE Leap 15.0:cgit-1.2.1-lp150.2.3.1
Ссылки
- CVE-2018-14912
- SUSE Bug 1103799