A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2024-4982 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2279411 | Permissions Required |
| https://bugzilla.redhat.com/show_bug.cgi?id=2280726 | Exploit Issue Tracking Vendor Advisory |
| https://pagure.io/pagure/c/c43844d23c919133fc983fe8c0f1dfb3b86e67d0 | Patch |
Configurations
History
07 Aug 2025, 00:09
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://access.redhat.com/security/cve/CVE-2024-4982 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2279411 - Permissions Required | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2280726 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://pagure.io/pagure/c/c43844d23c919133fc983fe8c0f1dfb3b86e67d0 - Patch | |
| CPE | cpe:2.3:a:redhat:pagure:*:*:*:*:*:*:*:* | |
| First Time |
Redhat pagure
Redhat |
13 May 2025, 19:35
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-12 19:15
Updated : 2025-08-07 00:09
NVD link : CVE-2024-4982
Mitre link : CVE-2024-4982
CVE.ORG link : CVE-2024-4982
JSON object : View
Products Affected
redhat
- pagure
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
