A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2024-4982 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2279411 | Permissions Required |
| https://bugzilla.redhat.com/show_bug.cgi?id=2280726 | Exploit Issue Tracking Vendor Advisory |
| https://pagure.io/pagure/c/c43844d23c919133fc983fe8c0f1dfb3b86e67d0 | Patch |
Configurations
History
No history.
Information
Published : 2025-05-12 19:15
Updated : 2025-08-07 00:09
NVD link : CVE-2024-4982
Mitre link : CVE-2024-4982
CVE.ORG link : CVE-2024-4982
JSON object : View
Products Affected
redhat
- pagure
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
