CVE-2013-4451

CRITICAL

Gitolite < 3.5.3 - Access Control

Title source: rule
STIX 2.1

Description

gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.

References (4)

Core 4
Core References
Mailing List, Patch mailing-list x_refsource_mlist
https://www.openwall.com/lists/oss-security/2013/10/21/11
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
https://www.securityfocus.com/bid/63237

Scores

CVSS v3 9.8
EPSS 0.0132
EPSS Percentile 80.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (1)
gitolite/gitolite 3.0 - 3.5.3
Published Sep 21, 2018
Tracked Since Feb 18, 2026