Vulnerabilities > Gitolite > Gitolite > 3.6.7

DATE CVE VULNERABILITY TITLE RISK
2019-01-10 CVE-2018-20683 Improper Input Validation vulnerability in Gitolite
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.
network
high complexity
gitolite CWE-20
8.1
2018-09-12 CVE-2018-16976 Race Condition vulnerability in Gitolite
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed.
network
low complexity
gitolite CWE-362
8.1