PT-2022-20655 · Gitblit · Gitblit
Yyhylh
·
Published
2022-05-21
·
Updated
2022-06-07
·
CVE-2022-31267
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gitblit version 1.9.2
Description
The issue allows privilege escalation via the Config User Service. A control character can be placed in a profile data field, such as an
emailAddress value, to potentially gain elevated access. For example, an attacker could use a value like attacker@example.com trole = "#admin" to exploit this issue.Recommendations
For Gitblit version 1.9.2, as a temporary workaround, consider restricting the use of control characters in profile data fields until a patch is available. Avoid using the
emailAddress field in a way that could allow privilege escalation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitblit