Information on source package pagure

Available versions

ReleaseVersion
bullseye5.11.3+dfsg-1
bookworm5.11.3+dfsg-2.1
trixie5.14.1+dfsg-1
sid5.14.1+dfsg-3

Open issues

BugbullseyebookwormtrixiesidDescription
CVE-2024-47516vulnerablevulnerablefixedfixedArgument Injection in PagureRepo.log()
CVE-2024-47515vulnerablevulnerablefixedfixedA vulnerability was found in Pagure. Support of symbolic links during ...
CVE-2024-4982vulnerablevulnerablefixedfixedPath traversal in view_issue_raw_file()
CVE-2024-4981vulnerablevulnerablefixedfixedpagure: _update_file_in_git() follows symbolic links in temporary clones

Resolved issues

BugDescription
CVE-2019-11556Pagure before 5.6 allows XSS via the templates/blame.html blame view.
CVE-2019-7628Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail serve ...
CVE-2017-1002151Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due t ...
CVE-2016-1000037Pagure: XSS possible in file attachment endpoint
CVE-2016-1000007Pagure 2.2.1 XSS in raw file endpoint

Search for package or bug name: Reporting problems