« Volver al listado

Redhat

Redhat Pagure: vulnerabilidades y CVE

Redhat Pagure tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses0
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-4982Media (6.5)0.74%—12 may 2025
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
CVE-2024-4981Alta (7.1)0.41%—12 may 2025
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git…
CVE-2024-47516Crítica (9.8)0.92%—26 mar 2025
A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.
CVE-2024-47515Alta (8.1)0.55%—24 dic 2024
A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.
CVE-2019-11556Media (6.1)0.97%—25 sept 2020
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
CVE-2016-1000037Media (6.1)1.1%—6 nov 2019
Pagure: XSS possible in file attachment endpoint
CVE-2019-7628Media (5.9)0.90%—8 feb 2019
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users.…
CVE-2017-1002151Alta (7.5)1.1%—14 sept 2017
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
CVE-2016-1000007Media (6.1)0.68%—7 oct 2016
Pagure 2.2.1 XSS in raw file endpoint

Otros productos de Redhat