CVE-2018-14912

cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.
Configurations

Configuration 1

cpe:2.3:a:cgit_project:cgit:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Information

Published : 2018-08-03 07:29

Updated : 2018-10-02 06:39


NVD link : CVE-2018-14912

Mitre link : CVE-2018-14912

Products Affected
No products.
CWE