peter bassill · operator
$ cve CVE-2018-14912 JSON

CVE-2018-14912 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 92% (pctl 100)

Patch early

A public exploit exists.

Description

cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS92.03% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2018-08-03
Last modified2026-06-17

Affected (2)

VendorProduct
cgit projectcgit
debiandebian linux

Public exploits

SourceTitleDate
exploit-dbcgit 1.2.1 - Directory Traversal (Metasploit)2018-08-14

References

→ the Explorer  ·  watch your stack  ·  NVD