icon

We found results for “

CVE-2022-41943

Date: November 21, 2022

sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental "customGitFetch" feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.

Language: Go

Severity Score

Severity Score

Weakness Type (CWE)

Incorrect Default Permissions

CWE-276

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): LOW

Do you need more information?

Contact Us