Search Results (5 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2011-1572 1 Gitolite 1 Gitolite 2025-04-11 N/A
Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands.
CVE-2012-4506 2 Gitolite, Sitaram Chamarty 2 Gitolite, Gitolite 2025-04-11 N/A
Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.
CVE-2013-7203 1 Gitolite 1 Gitolite 2024-11-21 N/A
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
CVE-2013-4451 1 Gitolite 1 Gitolite 2024-11-21 N/A
gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.
CVE-2010-2447 1 Gitolite 1 Gitolite 2024-11-21 9.8 Critical
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.