CVE-2024-47515

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.
Configurations

No configuration.

History

06 Feb 2025, 09:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2024-47515 -
Summary
  • (es) Se encontró una vulnerabilidad en Pagure. El soporte de enlaces simbólicos durante el archivado de repositorios permite la divulgación de archivos locales. Esta falla permite que un usuario malintencionado aproveche la instancia de Pagure.

24 Dec 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-24 04:15

Updated : 2025-02-06 09:15


NVD link : CVE-2024-47515

Mitre link : CVE-2024-47515

CVE.ORG link : CVE-2024-47515


JSON object : View

Products Affected

No product.

CWE
CWE-61

UNIX Symbolic Link (Symlink) Following