Description
The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.
Published: 2020-08-14
Score: 5.9 Medium
EPSS: 3.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-30488 The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.
History

No history.

Subscriptions

Adobe Git-server
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-09-16T16:43:25.441Z

Reserved: 2020-03-02T00:00:00.000Z

Link: CVE-2020-9708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-08-14T17:15:14.530

Modified: 2024-11-21T05:41:08.267

Link: CVE-2020-9708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses