Impact
The project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances.
Patches
Workarounds
The project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability.
References
This issue was reported by ggamno via HackerOne.
Impact
The project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances.
Patches
Workarounds
The project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability.
References
This issue was reported by ggamno via HackerOne.