The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2020-08-14T16:48:30.769927Z

Updated: 2024-09-16T16:43:25.441Z

Reserved: 2020-03-02T00:00:00

Link: CVE-2020-9708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-08-14T17:15:14.530

Modified: 2020-08-21T14:55:04.073

Link: CVE-2020-9708

cve-icon Redhat

No data.