Dylan Alex Simon discovered and reported a directory traversal flaw in the way Gitolite restricted access to admin defined commands ("ADC"). An authenticated attacker could execute arbitrary code with privileges of Gitolite server user using specially crafted command name.
The flaw does not affect default Gitolite installations. Users who have enabled ADC in their configurations are advised to install the updated package which includes a fix to resolve the issue.
Please login to add feedback.
This update has been submitted for testing by lkundrak.
This update has been pushed to testing
Works for me.
This update has been submitted for stable by lkundrak.
This update has been pushed to stable