gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
References
Link | Resource |
---|---|
https://marc.info/?l=oss-security&m=138783069700756&w=2 | Third Party Advisory |
https://lists.fedoraproject.org/pipermail/package-announce/2014-January/125611.html | Third Party Advisory |
http://packetstormsecurity.com/files/149438/ManageEngine-SupportCenter-Plus-8.1.0-Cross-Site-Scripting.html | Not Applicable Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-09-21 10:29
Updated : 2018-11-19 07:08
NVD link : CVE-2013-7203
Mitre link : CVE-2013-7203
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
gitolite
- gitolite