CVE-2013-2117

Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
jason_a_donenfeldcgit
𝑥
≤ 0.9.1
lars_hjemlicgit
0.1
lars_hjemlicgit
0.2
lars_hjemlicgit
0.3
lars_hjemlicgit
0.4
lars_hjemlicgit
0.5
lars_hjemlicgit
0.6
lars_hjemlicgit
0.6.1
lars_hjemlicgit
0.6.2
lars_hjemlicgit
0.6.3
lars_hjemlicgit
0.7
lars_hjemlicgit
0.7.1
lars_hjemlicgit
0.7.2
lars_hjemlicgit
0.8
lars_hjemlicgit
0.8.1
lars_hjemlicgit
0.8.1.1
lars_hjemlicgit
0.8.2
lars_hjemlicgit
0.8.2.1
lars_hjemlicgit
0.8.2.2
lars_hjemlicgit
0.8.3
lars_hjemlicgit
0.8.3.1
lars_hjemlicgit
0.8.3.2
lars_hjemlicgit
0.8.3.3
lars_hjemlicgit
0.8.3.4
lars_hjemlicgit
0.8.3.5
lars_hjemlicgit
0.9
lars_hjemlicgit
0.9.0.1
lars_hjemlicgit
0.9.0.2
lars_hjemlicgit
0.9.0.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cgit
bullseye
1.2.3+git2.25.1-1
fixed
bookworm
1.2.3+git20221219.50.91f2590+git2.39.1-1
fixed
sid
1.2.3+git20240802.70.09d24d7+git2.46.0-1
fixed
trixie
1.2.3+git20240802.70.09d24d7+git2.46.0-1
fixed