InDefero Source Access Security Bypass
by Carol~
- 2/22/10 5:31 AM
In Reply to: VULNERABILITIES \ FIXES - February 22, 2010 by Carol~
Release Date : 2010-02-22
Criticality level : Less critical
Impact : Security Bypass
Where : From remote
Solution Status : Vendor Patch
Software : InDefero 0.x
Description :
A security issue has been reported in InDefero, which can be exploited by malicious users to bypass certain security restrictions.
The security issue is caused due to an error in the git serving component, which can be exploited to gain access to private sources that are marked "read only" for certain users, if the short name of the project is known.
Successful exploitation requires user access to the forge and a valid SSH key.
The security issue is reported in versions prior to 0.8.10.
Solution :
Update to version 0.8.10 or apply the patch.
Original Advisory
http://www.ceondo.com/ecte/2010/02/indefero-security-vulnerability
http://secunia.com/advisories/38664/

Moderator
CNET Staff
Samsung Staff
Dell Staff