S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-14912 Scanner

CVE-2018-14912 scanner - Directory Traversal vulnerability in CGit

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-14912
7.5
CVSS

cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

CGit is an open-source web front-end for git repositories that allows users to view repo files and commit history through a browser. It also enables users to search and view different branches of a project, as well as manage authorized users and access control. CGit is a lightweight, fast, and highly customizable web interface for git repositories. It is widely used by software development teams to manage multiple projects and track code changes across different branches.

CVE-2018-14912 is a critical vulnerability discovered in CGit before version 1.2.1. This vulnerability arises when `enable-http-clone=1` is enabled. Hackers can exploit a directory traversal vulnerability when they use a crafted HTTP request that allows them to retrieve files from outside of the intended directory tree. An attacker can use the `path=../` parameter to navigate to the root directory of the system hosting the CGit web application and view files outside of the intended scope. 

When this vulnerability is exploited, it can lead to unauthorized disclosure of sensitive information, such as access credentials, client details, and proprietary source code. Attackers can use this information to gain unauthorized access to different systems, which in turn can lead to more severe cyber-attacks. This vulnerability can also cause service denial to the application server, resulting in significant loss of revenue and reputation for affected businesses.

With the pro features of the s4e.io platform, users can easily and quickly stay informed about vulnerabilities in their digital assets. The platform provides real-time alerts, comprehensive vulnerability scanning, and expert guidance to help businesses identify and remediate any vulnerabilities promptly. Users can also leverage the platform to assess the security posture of their web applications and network infrastructure continually. The s4e.io platform is an essential tool for businesses looking to secure their digital assets and protect themselves from cyber-attacks.

 

REFERENCES

Solution Advice

The following measures can be taken to protect against the vulnerability:

  • Update to the latest version of CGit (1.2.1 or later)
  • Turn off `enable-http-clone=1` option in the CGit configuration file
  • Apply access controls and permission settings to the CGit web application
  • Implement strong password policies and multi-factor authentication for CGit users
  • Use a secure gateway to monitor and filter incoming traffic to the CGit web server

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-14912 scanner - Directory Traversal vulnerability in CGit | S4E