A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.
{ "binaries": [ { "binary_name": "pagure", "binary_version": "5.8.1+dfsg-3" }, { "binary_name": "pagure-ci", "binary_version": "5.8.1+dfsg-3" }, { "binary_name": "pagure-ev-server", "binary_version": "5.8.1+dfsg-3" }, { "binary_name": "pagure-loadjson", "binary_version": "5.8.1+dfsg-3" }, { "binary_name": "pagure-logcom", "binary_version": "5.8.1+dfsg-3" }, { "binary_name": "pagure-milters", "binary_version": "5.8.1+dfsg-3" }, { "binary_name": "pagure-mirror", "binary_version": "5.8.1+dfsg-3" }, { "binary_name": "pagure-webhook", "binary_version": "5.8.1+dfsg-3" } ] }
{ "binaries": [ { "binary_name": "pagure", "binary_version": "5.11.3+dfsg-1" }, { "binary_name": "pagure-ci", "binary_version": "5.11.3+dfsg-1" }, { "binary_name": "pagure-ev-server", "binary_version": "5.11.3+dfsg-1" }, { "binary_name": "pagure-loadjson", "binary_version": "5.11.3+dfsg-1" }, { "binary_name": "pagure-logcom", "binary_version": "5.11.3+dfsg-1" }, { "binary_name": "pagure-milters", "binary_version": "5.11.3+dfsg-1" }, { "binary_name": "pagure-mirror", "binary_version": "5.11.3+dfsg-1" }, { "binary_name": "pagure-webhook", "binary_version": "5.11.3+dfsg-1" } ] }
{ "binaries": [ { "binary_name": "pagure", "binary_version": "5.11.3+dfsg-2.1ubuntu0.1" }, { "binary_name": "pagure-ci", "binary_version": "5.11.3+dfsg-2.1ubuntu0.1" }, { "binary_name": "pagure-ev-server", "binary_version": "5.11.3+dfsg-2.1ubuntu0.1" }, { "binary_name": "pagure-loadjson", "binary_version": "5.11.3+dfsg-2.1ubuntu0.1" }, { "binary_name": "pagure-logcom", "binary_version": "5.11.3+dfsg-2.1ubuntu0.1" }, { "binary_name": "pagure-milters", "binary_version": "5.11.3+dfsg-2.1ubuntu0.1" }, { "binary_name": "pagure-mirror", "binary_version": "5.11.3+dfsg-2.1ubuntu0.1" }, { "binary_name": "pagure-webhook", "binary_version": "5.11.3+dfsg-2.1ubuntu0.1" } ] }
{ "binaries": [ { "binary_name": "pagure", "binary_version": "5.14.1+dfsg-7" }, { "binary_name": "pagure-ci", "binary_version": "5.14.1+dfsg-7" }, { "binary_name": "pagure-ev-server", "binary_version": "5.14.1+dfsg-7" }, { "binary_name": "pagure-loadjson", "binary_version": "5.14.1+dfsg-7" }, { "binary_name": "pagure-logcom", "binary_version": "5.14.1+dfsg-7" }, { "binary_name": "pagure-milters", "binary_version": "5.14.1+dfsg-7" }, { "binary_name": "pagure-mirror", "binary_version": "5.14.1+dfsg-7" }, { "binary_name": "pagure-webhook", "binary_version": "5.14.1+dfsg-7" } ] }