A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2024-4981 | vdb entry vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2278745 | permissions required |
https://bugzilla.redhat.com/show_bug.cgi?id=2280723 | exploit issue tracking |
https://pagure.io/pagure/c/454f2677bc50d7176f07da9784882eb2176537f4 | patch |