CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server. |
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git re...Show more |
2Opensuse Redhat3Backports Sle LeapPagureJun 17, 2026 Sep 25, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Pagure before 5.6 allows XSS via the templates/blame.html blame view. |
2Fedoraproject Redhat3Enterprise Linux FedoraPagureNov 21, 2024 Nov 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Pagure: XSS possible in file attachment endpoint |
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users....Show more |
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization |
Pagure 2.2.1 XSS in raw file endpoint |