Vulnerability Description
The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a crafted http request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bonobogitserver | Bonobo Git Server | < 6.5.0 |
Related Weaknesses (CWE)
References
- https://bonobogitserver.com/changelog/#version-650Vendor Advisory
- https://flab.cesnet.cz/advisories/cve-2019-11217PatchThird Party Advisory
- https://bonobogitserver.com/changelog/#version-650Vendor Advisory
- https://flab.cesnet.cz/advisories/cve-2019-11217PatchThird Party Advisory
FAQ
What is CVE-2019-11217?
CVE-2019-11217 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a crafted http request.
How severe is CVE-2019-11217?
CVE-2019-11217 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-11217?
Check the references section above for vendor advisories and patch information. Affected products include: Bonobogitserver Bonobo Git Server.