VYPR

Bonobo Git Server

by Jakubgarfield

Source repositories

CVEs (2)

  • CVE-2019-11217Apr 24, 2019
    risk 0.01cvss epss 0.07

    The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a crafted http request.

  • CVE-2019-11218Apr 24, 2019
    risk 0.00cvss epss 0.01

    Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.