PT-2018-10146 · Joey Hess+1 · Git-Annex+1

Daniel Dent

+1

·

Published

2018-07-06

·

Updated

2025-11-14

·

CVE-2018-10859

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions git-annex (affected versions not specified)
Description The issue concerns an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's GPG key, potentially exposing encrypted data that was never stored in git-annex. This attack requires the attacker to have control of a server hosting an encrypted special remote used by the victim's git-annex repository. The attacker can use git annex addurl --relaxed with an innocuous URL and then send the content of the GPG-encrypted file they wish to have decrypted when the user downloads the content from the special remote.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2018-10859
DLA-1495-1
HSEC-2023-0011
OPENSUSE-SU-2018_1896-1

Affected Products

Suse
Git-Annex