Upstream information
Description
Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands via the --plug-in argument to the highlight command.NVD CVSS v2 Base Score: 6.0 (AV:N/AC:M/Au:S/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 787074 SUSE Security Advisories:- openSUSE-SU-2012:1460-1, published Mon, 12 Nov 2012 11:08:33 +0100 (CET)
- openSUSE-SU-2012:1461-1, published Mon, 12 Nov 2012 11:08:49 +0100 (CET)
