github.com
https://github.com/gitblit/gitblit CVE-2022-31268
HIGHNuclei
Path traversal in Gitblit
Record summary
CVE-2022-31268 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
com.gitblit:gitblitBrowse Maven / com.gitblit:gitblit | GitHub Advisory | Through 1.9.3 | affected |
Nuclei templates
1ProjectDiscoveryHIGHGitblit 1.9.3 - Local File InclusionCVSS 7.5
Gitblit 1.9.3 is vulnerable to local file inclusion via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the affected system.
Remediation
Upgrade Gitblit to a version that is not affected by the vulnerability (CVE-2022-31268).
WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2022lfigitblitvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:gitblit:gitblit:1.9.3:*:*:*:*:*:*:*
Shodan: http.html:"Gitblit"
Shodan: http.title:"gitblit"
Shodan: http.html:"gitblit"
FOFA: title="gitblit"
FOFA: body="gitblit"
Google: intitle:"gitblit"
https://github.com/metaStor/Vuls/blob/main/gitblit/gitblit%20V1.9.3%20path%20traversal/gitblit%20V1.9.3%20path%20traversal.md https://vuldb.com/?id.200500 https://nvd.nist.gov/vuln/detail/CVE-2022-31268 https://github.com/Marcuccio/kevin https://github.com/20142995/sectool
Source: ProjectDiscovery
References
3github.com
https://github.com/metaStor/Vuls/blob/main/gitblit/gitblit%20V1.9.3%20path%20traversal/gitblit%20V1.9.3%20path%20traversal.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-31268