Vulnerability Description
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitblit | Gitblit | 1.9.3 |
Related Weaknesses (CWE)
References
- https://github.com/metaStor/Vuls/blob/main/gitblit/gitblit%20V1.9.3%20path%20traExploitThird Party Advisory
- https://github.com/metaStor/Vuls/blob/main/gitblit/gitblit%20V1.9.3%20path%20traExploitThird Party Advisory
FAQ
What is CVE-2022-31268?
CVE-2022-31268 is a vulnerability with a CVSS score of 7.5 (HIGH). A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
How severe is CVE-2022-31268?
CVE-2022-31268 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31268?
Check the references section above for vendor advisories and patch information. Affected products include: Gitblit Gitblit.