PT-2022-26173 · Sourcegraph · Sourcegraph

Published

2022-11-22

·

Updated

2022-11-26

·

CVE-2022-41943

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Sourcegraph versions prior to 4.1.0
Description The issue allows a site admin to execute arbitrary commands on Gitserver when the experimental customGitFetch feature is enabled. This feature has been disabled by default.
Recommendations For versions prior to 4.1.0, update to version 4.1.0 to resolve the issue. As a temporary workaround, consider disabling the customGitFetch feature until the update is applied.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-41943
GHSA-4QHQ-4X4H-FXM8

Affected Products

Sourcegraph