漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Soft Serve allows path traversal attacks
Vulnerability Description
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Soft Serve 路径遍历漏洞
Vulnerability Description
Soft Serve是Charm开源的一个可自托管的命令行 Git 服务器。 Soft Serve 0.8.2之前版本存在路径遍历漏洞,该漏洞源于容易受到路径遍历攻击,允许现有非管理员用户访问并接管其他用户的仓库。
CVSS Information
N/A
Vulnerability Type
N/A