Vulnerabilities > Gource > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-07 CVE-2010-2449 Improper Input Validation vulnerability in Gource
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.
network
low complexity
gource CWE-20
5.5