← Back

Fedorarepository

fedorarepository

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Fcrepo
fcrepo

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fedorarepository
1Fcrepo
Jun 17, 2026
Jan 23, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and...Show more
Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).Show less
1Fedorarepository
1Fcrepo
Jun 17, 2026
Jan 23, 2025
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location...Show more
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).Show less