QID 730551
Date Published: 2022-07-04
QID 730551: Gitblit Path Traversal Vulnerability
Gitblit is an open source, pure Java Git solution for managing, viewing, and serving Git repositories.
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
Affected Versions:
GitBlit 1.9.3
QID Detection Logic (Unauthenticated): The QID checks for vulnerable GitBlit instance by sending a crafted payload to the webserver.
Successful exploitation of the vulnerability may allow remote attacker to view sensitive files on the webserver
Solution
Vendor has not released patch yet. For more information please refer to CVE-2022-31268
Vendor References
CVEs related to QID 730551
Software Advisories
| Advisory ID | Software | Component | Link |
|---|