The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: adobe
Published: 2020-08-14T16:48:30.769927Z
Updated: 2024-09-16T16:43:25.441Z
Reserved: 2020-03-02T00:00:00
Link: CVE-2020-9708
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-08-14T17:15:14.530
Modified: 2024-11-21T05:41:08.267
Link: CVE-2020-9708
Redhat
No data.