CWE-527: Exposure of Version-Control Repository to an Unauthorized Control Sphere

low-risk

The product stores a CVS, git, or other repository in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.

Abstraction: Variant

Common Consequences

Confidentiality Read Application Data

Real-World Examples (2)

CVE CVSS EPSS KEV
CVE-2021-21423 6.8 0.7%
CVE-2022-20931 6.5 0.1%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal