26 Mar
26Mar


A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.  # CVE-2024-47516
CVE-2024-47516 CVSS 9.8  SEVERITY - CRITICALCVSS VECTOR - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration - 
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Comments
* The email will not be published on the website.