ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8757-1: cgit vulnerability

lowAdvisoryimportance 18
AI summary · glm-5.3

Ubuntu USN-8757-1 fixes cgit path-handling flaw letting remote attackers read files outside repositories during HTTP cloning.

Ubuntu Security Notice USN-8757-1 addresses a cgit vulnerability in which repository paths are incorrectly handled when HTTP cloning is enabled. A remote attacker could exploit the flaw to access files outside the repository and obtain sensitive information. The notice provides no CVE identifier or exploitation details.

  • cgit mishandles repository paths when HTTP cloning is enabled
  • Remote attackers can read files outside repository, exposing sensitive data
  • Fix shipped via Ubuntu Security Notice USN-8757-1
Full article

It was discovered that cgit incorrectly handled repository paths when HTTP cloning was enabled. A remote attacker could possibly use this issue to access files outside the repository and obtain sensitive information.

This source does not provide full text. Read it at ubuntu.com.