PT-2012-5475 · Cgit+1 · Cgit+1

Kurt Seifried

·

Publicado

2012-11-11

·

Atualizado

2024-06-15

·

CVE-2012-4548

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cgit versions 9.0.3 and earlier
Description The issue allows remote authenticated users with permissions to add files to execute arbitrary commands. This is achieved via the --plug-in argument to the highlight command in the syntax-highlighting.sh script.
Recommendations For versions 9.0.3 and earlier, consider disabling the highlight command or restricting access to the syntax-highlighting.sh script until a patch is available. As a temporary workaround, avoid using the --plug-in argument in the highlight command to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-4548
OPENSUSE-SU-2012_1460-1
OPENSUSE-SU-2012_1461-1
OPENSUSE-SU-2024:10137-1

Produtos afetados

Suse
Cgit