|
|
| |
|
| |
cgit: directory traversal
| Package(s): | cgit |
CVE #(s): | CVE-2013-2117
|
| Created: | June 6, 2013 |
Updated: | July 17, 2013 |
| Description: |
From the Red Hat Bugzilla entry:
Today I found a nasty directory traversal:
http://somehost/?url=/somerepo/about/../../../../etc/passwd
[...] Cgit by default is not vulnerable to this, and the vulnerability only
exists when a user has configured cgit to use a readme file from a
filesystem filepath instead of from the git repo itself. Until a
release is made, administrators are urged to disable reading the
readme file from a filepath, if currently enabled. |
| Alerts: |
|
( Log in to post comments)
|
|
|