CVE-2018-10859Sensitive Information Exposure in Project Git-annex

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.5%
top 33.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateNov 14

Description

git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted data that was never stored in git-annex

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Hackagegit-annex_project/git-annex0.201104176.20180626
Debiangit-annex_project/git-annex< 6.20180626-1+3

Also affects: Debian Linux 8.0

🔴Vulnerability Details

4
OSV
git-annex GPG decryption attack via compromised remote2025-11-14
GHSA
GHSA-j24g-q5jp-xg4v: git-annex is vulnerable to an Information Exposure when decrypting files2022-05-13
OSV
CVE-2018-10859: git-annex is vulnerable to an Information Exposure when decrypting files2018-07-16
CVEList
CVE-2018-10859: git-annex is vulnerable to an Information Exposure when decrypting files2018-07-16

📋Vendor Advisories

1
Debian
CVE-2018-10859: git-annex - git-annex is vulnerable to an Information Exposure when decrypting files. A mali...2018

💬Community

4
Bugzilla
CVE-2018-10857 CVE-2018-10859 git-annex: various flaws [fedora-all]2018-06-27
Bugzilla
CVE-2018-10859 git-annex: Malicious server could trick git-annex into decrypting a file encrypted to the user's gpg key2018-06-27
Bugzilla
CVE-2018-10857 git-annex: Private data exposure and exfiltration2018-06-27
Bugzilla
CVE-2018-10857 CVE-2018-10859 git-annex: various flaws [epel-all]2018-06-27
CVE-2018-10859 — Sensitive Information Exposure | cvebase