Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-j4jw-m6xr-fv6c: Soft Serve vulnerable to path traversal attacks

Impact

Path traversal attack gives access to existing non-admin users to access and take over other user’s repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions.

Patches

This is patched in v0.8.2

Workarounds

Single user set-ups are not affected. This only affects multi-user Soft Serve set-ups that enable repository creation for users. Otherwise, upgrading is necessary to circumvent the attack.

ghsa
#git

Package

gomod github.com/charmbracelet/soft-serve (Go)

Affected versions

< 0.8.2

Description

Impact

Path traversal attack gives access to existing non-admin users to access and take over other user’s repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions.

Patches

This is patched in v0.8.2

Workarounds

Single user set-ups are not affected. This only affects multi-user Soft Serve set-ups that enable repository creation for users. Otherwise, upgrading is necessary to circumvent the attack.

References

  • GHSA-j4jw-m6xr-fv6c
  • charmbracelet/soft-serve@a8d1bf3
  • https://github.com/charmbracelet/soft-serve/releases/tag/v0.8.2

Published to the GitHub Advisory Database

Jan 8, 2025

ghsa: Latest News

GHSA-6gf2-ffq8-gcww: GHSL-2024-288: SickChill open redirect in login