cbcvebase.
CVE-2024-47516
published 2025-03-26

CVE-2024-47516: A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.84%
53.8th percentile
A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianpagure< pagure 5.11.3+dfsg-1+deb11u1 (bullseye)pagure 5.11.3+dfsg-1+deb11u1 (bullseye)
redhatpagure>= 0 < 5.11.3+dfsg-1+deb11u15.11.3+dfsg-1+deb11u1
redhatpagure>= 0 < 5.14.1+dfsg-15.14.1+dfsg-1
redhatpagure>= 0 < 5.11.3+dfsg-1ubuntu0.15.11.3+dfsg-1ubuntu0.1
redhatpagure>= 0 < 5.11.3+dfsg-2.1ubuntu0.25.11.3+dfsg-2.1ubuntu0.2
redhatpagure>= 0 < 5.8.1+dfsg-3ubuntu0.1~esm15.8.1+dfsg-3ubuntu0.1~esm1

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-47516 is an argument injection vulnerability in Pagure's Git integration, triggered during retrieval of repository history, leading to remote code execution. Detection should focus on anomalous or crafted Git arguments passed through Pagure's history retrieval endpoints.
  • Monitor Pagure instances for unexpected process spawning from the Pagure web process, particularly git subprocesses with unusual argument patterns (e.g., arguments beginning with '--' or '-' that could be interpreted as git flags) originating from history/log retrieval requests.
  • Pagure versions prior to 5.11.3+dfsg-1+deb11u1 (Debian bullseye), 5.14.1+dfsg-1 (Debian sid/trixie) are vulnerable. Identify unpatched Pagure deployments as a priority for detection and remediation.
  • ·The Debian security tracker classifies the scope of this vulnerability as 'local', which may indicate exploitation requires some level of authenticated or local access, despite the Ubuntu advisory describing the attacker as 'remote'.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.