Redhat
Redhat Pagure: vulnerabilidades y CVE
Redhat Pagure tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-4982 | Media (6.5) | 0.74% | — | 12 may 2025 | A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server. |
| CVE-2024-4981 | Alta (7.1) | 0.41% | — | 12 may 2025 | A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git… |
| CVE-2024-47516 | Crítica (9.8) | 0.92% | — | 26 mar 2025 | A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance. |
| CVE-2024-47515 | Alta (8.1) | 0.55% | — | 24 dic 2024 | A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance. |
| CVE-2019-11556 | Media (6.1) | 0.97% | — | 25 sept 2020 | Pagure before 5.6 allows XSS via the templates/blame.html blame view. |
| CVE-2016-1000037 | Media (6.1) | 1.1% | — | 6 nov 2019 | Pagure: XSS possible in file attachment endpoint |
| CVE-2019-7628 | Media (5.9) | 0.90% | — | 8 feb 2019 | Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users.… |
| CVE-2017-1002151 | Alta (7.5) | 1.1% | — | 14 sept 2017 | Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization |
| CVE-2016-1000007 | Media (6.1) | 0.68% | — | 7 oct 2016 | Pagure 2.2.1 XSS in raw file endpoint |
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230