Record summary

CVE-2022-31268 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryThrough 1.9.3affected

Nuclei templates

1
ProjectDiscoveryHIGHGitblit 1.9.3 - Local File InclusionCVSS 7.5

Gitblit 1.9.3 is vulnerable to local file inclusion via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the affected system.

Remediation

Upgrade Gitblit to a version that is not affected by the vulnerability (CVE-2022-31268).

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2022lfigitblitvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:gitblit:gitblit:1.9.3:*:*:*:*:*:*:*
Shodan: http.html:"Gitblit"
Shodan: http.title:"gitblit"
Shodan: http.html:"gitblit"
FOFA: title="gitblit"
FOFA: body="gitblit"
Google: intitle:"gitblit"

Source: ProjectDiscovery

References

3