CVE Request: cgit directory traversal
Jason A. Donenfeld
Jason at zx2c4.com
Sat May 25 20:16:20 CEST 2013
As mentioned in early messages to oss-sec, I've inherited
maintainership of the cgit codebase and am gradually auditing it.
Today I found a nasty directory traversal:
This should be pretty straightforward to categorize.
Exploitation looks like:
I've committed a fix for it here:
And this fix will be in the master branch and a new release will be made soon.
Cgit by default is not vulnerable to this, and the vulnerability only
exists when a user has configured cgit to use a readme file from a
filesystem filepath instead of from the git repo itself. Until a
release is made, administrators are urged to disable reading the
readme file from a filepath, if currently enabled.
More information about the CGit