Sitaram Chamarty

4 exploits Active since Sep 2018
CVE-2010-2447 WRITEUP CRITICAL WRITEUP
gitolite < 1.4.1 - Path Traversal via Unfiltered src/ and hooks/ Paths
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
CVSS 9.8
CVE-2013-4451 WRITEUP CRITICAL WRITEUP
gitolite 3.0-3.5.3 - Unspecified Impact via World-Writable File Permissions
gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.
CVSS 9.8
CVE-2018-16976 WRITEUP HIGH WRITEUP
Gitolite < 3.6.9 - Unintended Repository Access via Race Condition in Migration Process
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.
CVSS 8.1
CVE-2018-20683 WRITEUP HIGH WRITEUP
gitolite < 3.6.11 - Command Injection via rsync Command Line
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.
CVSS 8.1