First published: Fri Aug 03 2018(Updated: )
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/cgit | 1.2.1+git2.18.0-1 1.2.3+git2.25.1-1 1.2.3+git20221219.50.91f2590+git2.39.1-1 | |
Cgit Project Cgit | <1.2.1 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.