PT-2022-20655 · Gitblit · Gitblit

Yyhylh

·

Published

2022-05-21

·

Updated

2022-06-07

·

CVE-2022-31267

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitblit version 1.9.2
Description The issue allows privilege escalation via the Config User Service. A control character can be placed in a profile data field, such as an emailAddress value, to potentially gain elevated access. For example, an attacker could use a value like attacker@example.com trole = "#admin" to exploit this issue.
Recommendations For Gitblit version 1.9.2, as a temporary workaround, consider restricting the use of control characters in profile data fields until a patch is available. Avoid using the emailAddress field in a way that could allow privilege escalation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31267
GHSA-FH55-VWJC-69C7

Affected Products

Gitblit