MGASA-2018-0434
Dashboard / Vulnerabilities / MGASA-2018-0434
Summary: Updated gitolite packages fix security vulnerability
Details: Updated gitolite package fixes security vulnerability: Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access (CVE-2018-16976).
References: https://advisories.mageia.org/MGASA-2018-0434.html, https://bugs.mageia.org/show_bug.cgi?id=23680, https://lists.fedoraproject.org/archives/list/[email protected]/thread/FW77TT3SZUDFVK3UYO6WNT7GFUHWXDUO/
Affected packages
Package
Name: gitolite
Purl: pkg:rpm/mageia/gitolite?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
