CVE-2018-20683

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/01/2019
Last modified:
07/11/2023

Description

commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitolite:gitolite:*:*:*:*:*:*:*:* 3.6.11 (excluding)