PT-2012-5475 · Cgit+1 · Cgit+1

Kurt Seifried

·

Published

2012-11-11

·

Updated

2024-06-15

·

CVE-2012-4548

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cgit versions 9.0.3 and earlier
Description The issue allows remote authenticated users with permissions to add files to execute arbitrary commands. This is achieved via the --plug-in argument to the highlight command in the syntax-highlighting.sh script.
Recommendations For versions 9.0.3 and earlier, consider disabling the highlight command or restricting access to the syntax-highlighting.sh script until a patch is available. As a temporary workaround, avoid using the --plug-in argument in the highlight command to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-4548
OPENSUSE-SU-2012_1460-1
OPENSUSE-SU-2012_1461-1
OPENSUSE-SU-2024:10137-1

Affected Products

Suse
Cgit