Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-8762 | Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T19:09:28.927Z
Reserved: 2018-09-12T00:00:00Z
Link: CVE-2018-16976
No data.
Status : Modified
Published: 2018-09-12T22:29:00.517
Modified: 2024-11-21T03:53:37.817
Link: CVE-2018-16976
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD