PT-2018-10146 · Joey Hess+1 · Git-Annex+1
Daniel Dent
+1
·
Published
2018-07-06
·
Updated
2025-11-14
·
CVE-2018-10859
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
git-annex (affected versions not specified)
Description
The issue concerns an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's GPG key, potentially exposing encrypted data that was never stored in git-annex. This attack requires the attacker to have control of a server hosting an encrypted special remote used by the victim's git-annex repository. The attacker can use
git annex addurl --relaxed with an innocuous URL and then send the content of the GPG-encrypted file they wish to have decrypted when the user downloads the content from the special remote.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Git-Annex