CVE-2022-41942
- EPSS 0.27%
- Veröffentlicht 22.11.2022 19:15:18
- Zuletzt bearbeitet 21.11.2024 07:24:07
Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the hos...
CVE-2022-41943
- EPSS 0.26%
- Veröffentlicht 22.11.2022 19:15:18
- Zuletzt bearbeitet 21.11.2024 07:24:07
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue...
CVE-2022-31154
- EPSS 0.14%
- Veröffentlicht 01.08.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:00
Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being able to edit both the trigger and the action of th...
CVE-2022-31155
- EPSS 0.17%
- Veröffentlicht 01.08.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:00
Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the ...
CVE-2022-29171
- EPSS 2.24%
- Veröffentlicht 06.05.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:38
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows Sourcegraph site admins to spe...
CVE-2022-23642
- EPSS 85.28%
- Veröffentlicht 18.02.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:49:00
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This a...
CVE-2022-23643
- EPSS 0.26%
- Veröffentlicht 15.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:49:00
Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channel vulnerabilitity in the Code Monitoring feature where strings in private source code could be guessed by an authenticat...
- EPSS 0.31%
- Veröffentlicht 13.12.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:52
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in private source code could be guessed by an authenticated but unauthorized actor. This issue affects the Sa...
CVE-2021-32787
- EPSS 0.2%
- Veröffentlicht 02.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:44
Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leaks. The site-admin area can be accessed by regular users and all information and features are properly protected except for daily u...
CVE-2020-12283
- EPSS 0.26%
- Veröffentlicht 30.04.2020 05:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:26
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.