CVE detail
CVE-2020-9708 — CVE-2020-9708
Published 2020-08-14 · Modified 2026-06-17 · Vendor adobe · Product git-server · Source nvd
MEDIUM
severity
CVSS-derived band
0.0294
EPSS probability
exploitation probability, 30d
86.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References