git-annex is vulnerable to an Information Exposure when decrypting files....
Vulnerability Description
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted data that was never stored in git-annex
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-10859
Credits & Attribution
No credits recorded in the NVD database.
References
More from [UNKNOWN]
View All →Affected Vendor
[UNKNOWN]
View all reports →