CVE-2018-10857Sensitive Information Exposure in Project Git-annex

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.5%
top 33.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateNov 14

Description

git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Hackagegit-annex_project/git-annex0.201104176.20180626+1
Debiangit-annex_project/git-annex< 6.20180626-1+3

Also affects: Debian Linux 8.0

🔴Vulnerability Details

5
OSV
git-annex private data exfiltration to compromised remote2025-11-14
OSV
git-annex GPG decryption attack via compromised remote2025-11-14
GHSA
GHSA-f7cm-x4r7-4852: git-annex is vulnerable to a private data exposure and exfiltration attack2022-05-13
OSV
CVE-2018-10857: git-annex is vulnerable to a private data exposure and exfiltration attack2018-07-16
CVEList
CVE-2018-10857: git-annex is vulnerable to a private data exposure and exfiltration attack2018-07-16

📋Vendor Advisories

1
Debian
CVE-2018-10857: git-annex - git-annex is vulnerable to a private data exposure and exfiltration attack. It c...2018

💬Community

4
Bugzilla
CVE-2018-10857 CVE-2018-10859 git-annex: various flaws [fedora-all]2018-06-27
Bugzilla
CVE-2018-10859 git-annex: Malicious server could trick git-annex into decrypting a file encrypted to the user's gpg key2018-06-27
Bugzilla
CVE-2018-10857 git-annex: Private data exposure and exfiltration2018-06-27
Bugzilla
CVE-2018-10857 CVE-2018-10859 git-annex: various flaws [epel-all]2018-06-27
CVE-2018-10857 — Sensitive Information Exposure | cvebase