Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4390-1 | pagure security update |
EUVD |
EUVD-2025-14275 | A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo. |
Thu, 07 Aug 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat pagure |
|
| CPEs | cpe:2.3:a:redhat:pagure:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Redhat
Redhat pagure |
Mon, 12 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Mon, 12 May 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo. | |
| Title | Pagure: _update_file_in_git() follows symbolic links in temporary clones | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-05-12T19:05:43.641Z
Reserved: 2024-05-15T22:44:08.761Z
Link: CVE-2024-4981
Updated: 2025-05-12T19:05:37.289Z
Status : Analyzed
Published: 2025-05-12T19:15:47.747
Modified: 2025-08-07T00:19:37.390
Link: CVE-2024-4981
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD