Vulnerability: cgit < 1.2.1 - Directory Traversal

cGit < 1.2.1 via cgit_clone_objects has a directory traversal vulnerability when enable-http-clone=1 is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.

Impact

No impact specified

Severity

high

Verified

Unknown