Fedora 14 : git-18.104.22.168-1.fc14 (2010-18981)
Medium Nessus Plugin ID 51373
SynopsisThe remote Fedora host is missing a security update.
DescriptionUpdate to 22.214.171.124 release which fixes various issues, notably :
- cross-site scripting (XSS) flaw was found in the web interface of Git distributed revision control system. A remote attacker could use this flaw to execute arbitrary HTML or scripting code by providing a certain URL with specially crafted values of f and fp variables.
Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected git package.