Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2010-2447

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
Attacker Value
Unknown

CVE-2018-20683

Disclosure Date: January 10, 2019 (last updated November 08, 2023)
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.
0
Attacker Value
Unknown

CVE-2013-7203

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
0
Attacker Value
Unknown

CVE-2013-4451

Disclosure Date: September 21, 2018 (last updated November 08, 2023)
gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.
0
Attacker Value
Unknown

CVE-2018-16976

Disclosure Date: September 12, 2018 (last updated November 08, 2023)
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.
0
Attacker Value
Unknown

CVE-2012-4506

Disclosure Date: October 22, 2012 (last updated October 05, 2023)
Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.
0
Attacker Value
Unknown

CVE-2011-1572

Disclosure Date: October 04, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands.
0