PT-2019-12193 · Bonobo · Bonobo Git Server

Published

2019-04-24

·

Updated

2019-04-25

·

CVE-2019-11217

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bonobo Git Server versions prior to 6.5.0
Description The issue allows execution of arbitrary commands in the context of the web server via a crafted HTTP request. This is due to a problem in the GitController.
Recommendations For versions prior to 6.5.0, update to version 6.5.0 or later to resolve the issue.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11217

Affected Products

Bonobo Git Server