Vulnerabilities (CVE)

Filtered by vendor Gitolite Subscribe
Filtered by product Gitolite
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16976 1 Gitolite 1 Gitolite 2019-10-03 5.5 MEDIUM 8.1 HIGH
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.
CVE-2018-20683 1 Gitolite 1 Gitolite 2019-02-15 6.8 MEDIUM 8.1 HIGH
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.