A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
https://pagure.io/pagure/c/c43844d23c919133fc983fe8c0f1dfb3b86e67d0
https://bugzilla.redhat.com/show_bug.cgi?id=2280726