Cgit Project / Cgit
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-14912 | cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cg… | HIGH | 7.5 | Aug 3, 2018 |
| CVE-2016-1901 | Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Leng… | CRITICAL | 9.8 | Jan 20, 2016 |
| CVE-2016-1900 | CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a r… | LOW | 3.7 | Jan 20, 2016 |
| CVE-2016-1899 | CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response spli… | LOW | 3.7 | Jan 20, 2016 |
Showing 1 to 4 of 4 CVEs