A vulnerability was found in Pagure. Support of symbolic...
High severity
Unreviewed
Published
Dec 24, 2024
to the GitHub Advisory Database
•
Updated Feb 6, 2025
Description
Published by the National Vulnerability Database
Dec 24, 2024
Published to the GitHub Advisory Database
Dec 24, 2024
Last updated
Feb 6, 2025
A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.
References