PT-2013-3546 · Cgit · Cgit
Jason A. Donenfeld
·
Published
2013-08-09
·
Updated
2024-06-15
·
CVE-2013-2117
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
cgit versions prior to 0.9.2
Description
A directory traversal issue exists in the cgit parse readme function, allowing remote attackers to read arbitrary files. This occurs when a readme file is set to a filesystem path and the url parameter contains a .. (dot dot) sequence.
Recommendations
For versions prior to 0.9.2, update to version 0.9.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the cgit parse readme function until a patch is available. Avoid using filesystem paths for readme files in the affected versions.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cgit