CVE-2022-41943
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/11/2022
Last modified:
26/11/2022
Description
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sourcegraph:sourcegraph:*:*:*:*:*:*:*:* | 4.1.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



