We found results for “”
CVE-2022-41943
Date: November 21, 2022
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental "customGitFetch" feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
Incorrect Default Permissions
CWE-276CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | LOW |
Vulnerabilities
Projects
Contact Us


