Related Vulnerabilities: CVE-2018-10857  

Some uses of git-annex were vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.

Severity High

Remote Yes

Type Arbitrary filesystem access

Description

Some uses of git-annex were vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.

AVG-725 git-annex 6.20180529-18 6.20180626-1 High Fixed

04 Jul 2018 ASA-201807-2 AVG-725 git-annex High multiple issues

https://git-annex.branchable.com/security/CVE-2018-10857_and_CVE-2018-10859/
https://git.joeyh.name/index.cgi/git-annex.git/commit/?id=b54b2cdc0ef1373fc200c0d28fded3c04fd57212