The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-09-16T16:43:25.441Z
Reserved: 2020-03-02T00:00:00
Link: CVE-2020-9708

No data.

Status : Modified
Published: 2020-08-14T17:15:14.530
Modified: 2024-11-21T05:41:08.267
Link: CVE-2020-9708

No data.