git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted data that was never stored in git-annex
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jul 16, 2018 | |
| Debian | debian-upgrade-git-annex | Feb 19, 2019 | Jul 16, 2018 | |
| Suse | — | suse-upgrade-git-annexsuse-upgrade-git-annex-bash-completion | Jul 7, 2018 | Jul 6, 2018 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Jul 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub