Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Pagure: _update_file_in_git() follows symbolic links in temporary clones
Vulnerability Description
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Vulnerability Type
对外部实体的文件或目录可访问
Vulnerability Title
Pagure 安全漏洞
Vulnerability Description
Pagure是Pagure开源的一款使用Python编写的提供Web服务的Git仓库。 Pagure存在安全漏洞,该漏洞源于恶意用户提交包含符号链接的git仓库,可能导致服务器意外显示外部内容。
CVSS Information
N/A
Vulnerability Type
N/A