CVE-2019-11217: Command Injection
Published Apr 24, 2019
·Updated
The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a crafted http request.
Affected Software
1 affected component
Bonobogitserver Bonobo Git Server<6.5.0
Remediation
Patch Available
Event History
Apr 24, 2019
CVE Published
via MITRE·07:13 PM
Data Sourced
via MITRE·07:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11217?
CVE-2019-11217 is classified as a high severity vulnerability that allows execution of arbitrary commands on the web server.
2
How do I fix CVE-2019-11217?
To fix CVE-2019-11217, upgrade Bonobo Git Server to version 6.5.0 or later.
3
What systems are affected by CVE-2019-11217?
CVE-2019-11217 affects all versions of Bonobo Git Server prior to 6.5.0.
4
What kind of attack vector is related to CVE-2019-11217?
CVE-2019-11217 can be exploited through crafted HTTP requests sent to the GitController.
5
What are the potential impacts of CVE-2019-11217?
Successful exploitation of CVE-2019-11217 can result in unauthorized command execution in the web server context.