← Back

Pagure

pagure

Vendor: Redhat • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Pagure
Jun 17, 2026
May 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
1Redhat
1Pagure
Jun 17, 2026
May 12, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git re...Show more
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.Show less
2Opensuse
Redhat
3Backports Sle
LeapPagure
Jun 17, 2026
Sep 25, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
2Fedoraproject
Redhat
3Enterprise Linux
FedoraPagure
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pagure: XSS possible in file attachment endpoint
1Redhat
1Pagure
Jun 17, 2026
Feb 8, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users....Show more
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py; disabling that job is also a viable solution. (E-mailing a substring of the API key was an attempted, but rejected, solution.)Show less
1Redhat
1Pagure
May 13, 2026
Sep 14, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
1Redhat
1Pagure
May 6, 2026
Oct 7, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pagure 2.2.1 XSS in raw file endpoint