CVE-2018-10857 — Sensitive Information Exposure in Project Git-annex
Severity
7.5HIGHNVD
CNA5.9
EPSS
0.5%
top 33.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 16
Latest updateNov 14
Description
git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
Also affects: Debian Linux 8.0
🔴Vulnerability Details
5GHSA▶
GHSA-f7cm-x4r7-4852: git-annex is vulnerable to a private data exposure and exfiltration attack↗2022-05-13
OSV▶
CVE-2018-10857: git-annex is vulnerable to a private data exposure and exfiltration attack↗2018-07-16
CVEList▶
CVE-2018-10857: git-annex is vulnerable to a private data exposure and exfiltration attack↗2018-07-16
📋Vendor Advisories
1Debian▶
CVE-2018-10857: git-annex - git-annex is vulnerable to a private data exposure and exfiltration attack. It c...↗2018
💬Community
4Bugzilla▶
CVE-2018-10859 git-annex: Malicious server could trick git-annex into decrypting a file encrypted to the user's gpg key↗2018-06-27