USN-8757-1: cgit vulnerability
AI summary · glm-5.3
Ubuntu USN-8757-1 fixes cgit path-handling flaw letting remote attackers read files outside repositories during HTTP cloning.
Ubuntu Security Notice USN-8757-1 addresses a cgit vulnerability in which repository paths are incorrectly handled when HTTP cloning is enabled. A remote attacker could exploit the flaw to access files outside the repository and obtain sensitive information. The notice provides no CVE identifier or exploitation details.
- cgit mishandles repository paths when HTTP cloning is enabled
- Remote attackers can read files outside repository, exposing sensitive data
- Fix shipped via Ubuntu Security Notice USN-8757-1
Full article
It was discovered that cgit incorrectly handled repository paths when HTTP cloning was enabled. A remote attacker could possibly use this issue to access files outside the repository and obtain sensitive information.
This source does not provide full text. Read it at ubuntu.com.