<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:42:25 +0000</lastBuildDate>
    <item>
      <title>CVE-2020-9708 — GHSL-2020-133: Insufficient validation of user input in resolveRepositoryPath function</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2020-9708</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Adobe Helix&lt;/p&gt;
&lt;p&gt;The resolveRepositoryPath function doesn&amp;#39;t properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Adobe Helix&lt;/p&gt;
&lt;p&gt;The resolveRepositoryPath function doesn&amp;#39;t properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2020-9708</guid>
    </item>
  </channel>
</rss>
