Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16976

Опубликовано: 12 сент. 2018
Источник: debian
EPSS Низкий

Описание

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitolite3fixed3.6.9-1package
gitolite3no-dsastretchpackage
gitolite3no-dsajessiepackage
gitoliteremovedpackage

Примечания

  • https://groups.google.com/forum/#!topic/gitolite-announce/WrwDTYdbfRg

  • https://github.com/sitaramc/gitolite/commit/dc13dfca8fdae5634bb0865f7e9822d2a268ed59

EPSS

Процентиль: 46%
0.00232
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

CVSS3: 8.1
nvd
больше 7 лет назад

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

suse-cvrf
больше 7 лет назад

Security update for gitolite

CVSS3: 8.1
github
больше 3 лет назад

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

EPSS

Процентиль: 46%
0.00232
Низкий