Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.
References
Link | Resource |
---|---|
http://hatriot.github.io/blog/2014/06/29/gitlist-rce/ | Exploit |
Configurations
Information
Published : 2014-07-22 07:55
Updated : 2014-07-22 08:20
NVD link : CVE-2014-5023
Mitre link : CVE-2014-5023
JSON object : View
CWE
Products Affected
gitlist
- gitlist