Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16976

Опубликовано: 12 сент. 2018
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gitolite:gitolite:*:*:*:*:*:*:*:*
Версия до 3.6.9 (исключая)

EPSS

Процентиль: 46%
0.00232
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

CVSS3: 8.1
debian
больше 7 лет назад

Gitolite before 3.6.9 does not (in certain configurations involving @a ...

suse-cvrf
больше 7 лет назад

Security update for gitolite

CVSS3: 8.1
github
больше 3 лет назад

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

EPSS

Процентиль: 46%
0.00232
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-362