Gitolite

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2010-2447

    gitolite before 1.4.1 does not filter src/ or hooks/ from path names.

    Last Modified: Nov 21, 2024
    Published: Nov 07, 2019

    CVE-2018-20683

    commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.

    Last Modified: Nov 21, 2024
    Published: Jan 10, 2019

    CVE-2013-4451

    gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.

    Last Modified: Nov 21, 2024
    Published: Sep 21, 2018

    CVE-2013-7203

    gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.

    Last Modified: Nov 21, 2024
    Published: Sep 21, 2018

    CVE-2018-16976

    Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

    Last Modified: Nov 21, 2024
    Published: Sep 12, 2018
    Items Per Page