{"id":"CVE-2024-4981","details":"A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.","modified":"2026-04-10T05:18:03.482223Z","published":"2025-05-12T19:15:47.747Z","references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-4981"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2278745"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2280723"},{"type":"FIX","url":"https://pagure.io/pagure/c/454f2677bc50d7176f07da9784882eb2176537f4"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-4981.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"5.14.1"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}