cgit project records
4 published records for vendor cgit project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 25%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2018-14912Weaponized | cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstratecgit project · cgit · CWE-22 | High7.5 | — | 92.0% | Aug 3, 2018 |
40Plan | CVE-2016-1901No exploit | Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value fedoraproject · fedora · CWE-119 | Critical9.8 | — | 3.8% | Jan 20, 2016 |
15Monitor | CVE-2016-1899No exploit | CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conductfedoraproject · fedora | Low3.7 | — | 1.9% | Jan 20, 2016 |
15Monitor | CVE-2016-1900No exploit | CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permissfedoraproject · fedora | Low3.7 | — | 1.9% | Jan 20, 2016 |
- CVE-2018-1491258Plan
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrate
HighCVSS 7.5WeaponizedEPSS 92%cgit project · cgitAug 3, 2018
- CVE-2016-190140Plan
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value
CriticalCVSS 9.8No exploitEPSS 4%fedoraproject · fedoraJan 20, 2016
- CVE-2016-189915Monitor
CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct
LowCVSS 3.7No exploitEPSS 2%fedoraproject · fedoraJan 20, 2016
- CVE-2016-190015Monitor
CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permiss
LowCVSS 3.7No exploitEPSS 2%fedoraproject · fedoraJan 20, 2016