cbcvebase.

Redhat Pagure vulnerabilities

7 known vulnerabilities affecting redhat/pagure.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2024-47516P2CRITICALCVSS 9.8≥ 0, < 5.11.3+dfsg-1+deb11u1≥ 0, < 5.14.1+dfsg-12025-03-26
CVE-2024-47516 [CRITICAL] CVE-2024-47516: A vulnerability was found in Pagure A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.
osv
CVE-2024-47515P3HIGHCVSS 8.1≥ 0, < 5.11.3+dfsg-1+deb11u1≥ 0, < 5.14.1+dfsg-12024-12-24
CVE-2024-47515 [HIGH] CVE-2024-47515: A vulnerability was found in Pagure A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.
osv
CVE-2024-4982P3MEDIUMCVSS 6.5fixed in 5.14.12025-05-12
CVE-2024-4982 [MEDIUM] CWE-22 CVE-2024-4982: A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a s A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
nvdosv
CVE-2017-1002151P3HIGHCVSS 7.5≤ 3.32017-09-14
CVE-2017-1002151 [HIGH] CWE-285 CVE-2017-1002151: Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
nvd
CVE-2024-4981P3HIGHCVSS 7.1fixed in 5.14.12025-05-12
CVE-2024-4981 [HIGH] CWE-552 CVE-2024-4981: A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.
nvdosv
CVE-2019-7628P4MEDIUMCVSS 5.9v5.22019-02-08
CVE-2019-7628 [MEDIUM] CWE-200 CVE-2019-7628: Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py; disabling that job is also a viable
nvd
CVE-2019-11556P4MEDIUMCVSS 6.1fixed in 5.62020-09-25
CVE-2019-11556 [MEDIUM] CWE-79 CVE-2019-11556: Pagure before 5.6 allows XSS via the templates/blame.html blame view. Pagure before 5.6 allows XSS via the templates/blame.html blame view.
nvdosv
Redhat Pagure vulnerabilities | cvebase