漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Soft Serve: Authenticated repo import can clone server-local private repositories
Vulnerability Description
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Soft Serve 安全漏洞
Vulnerability Description
Soft Serve是Charm开源的一个可自托管的命令行 Git 服务器。 Soft Serve 0.6.0版本至0.11.6之前版本存在安全漏洞,该漏洞源于仓库导入存在授权缺陷,可能导致任何经过身份验证的SSH用户克隆服务器本地Git仓库,包括其他用户的私有仓库,到其控制的新仓库中。
CVSS Information
N/A
Vulnerability Type
N/A