Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-64475
HistoryAug 03, 2021 - 12:00 a.m.

isomorphic-git path traversal vulnerability

2021-08-0300:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.001 Low

EPSS

Percentile

49.1%

isomorphic-git is a pure JavaScript implementation of open source git for node and browser environments (including WebWorkers and ServiceWorkers). isomorphic-git is vulnerable to path traversal prior to 1.8.2, which stems from the fact that isomorphic-git allows directory traversal via carefully crafted repositories for directory traversal. An attacker could exploit this vulnerability to obtain sensitive information.

CPENameOperatorVersion
isomorphic-git isomorphic-gitlt1.8.2

0.001 Low

EPSS

Percentile

49.1%