CVE-2018-16976
12.09.2018, 22:29
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.
Vendor | Product | Version |
---|---|---|
gitolite | gitolite | 𝑥 < 3.6.9 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
gitolite |
| ||||||||||||||||||||||||||||||
gitolite3 |
|
References