Critical severity9.0NVD Advisory· Published Nov 22, 2022· Updated Jun 17, 2026
CVE-2022-41943
CVE-2022-41943
Description
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental customGitFetch feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.
Affected products
2<4.1.0+ 1 more
- (no CPE)range: <4.1.0
- (no CPE)range: < 4.1.0
Patches
Vulnerability mechanics
References
2- github.com/sourcegraph/sourcegraph/pull/42704nvdIssue TrackingPatchThird Party Advisory
- github.com/sourcegraph/sourcegraph/security/advisories/GHSA-4qhq-4x4h-fxm8nvdThird Party Advisory
News mentions
0No linked articles in our index yet.