CVE-2011-1572

Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitolite:gitolite:*:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.50:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.55:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.60:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.65:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.70:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.80:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.85:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.90:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:0.95:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.0:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.1:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.2:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.3:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.4:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:gitolite:gitolite:1.5.8:*:*:*:*:*:*:*

History

21 Nov 2024, 01:26

Type Values Removed Values Added
References () http://groups.google.com/group/gitolite/browse_thread/thread/797a93ec26e1dcbc?pli=1 - () http://groups.google.com/group/gitolite/browse_thread/thread/797a93ec26e1dcbc?pli=1 -
References () http://seclists.org/oss-sec/2011/q2/197 - Patch () http://seclists.org/oss-sec/2011/q2/197 - Patch
References () http://seclists.org/oss-sec/2011/q2/209 - Patch () http://seclists.org/oss-sec/2011/q2/209 - Patch
References () http://www.debian.org/security/2011/dsa-2215 - () http://www.debian.org/security/2011/dsa-2215 -
References () http://www.securityfocus.com/bid/46473 - Patch () http://www.securityfocus.com/bid/46473 - Patch
References () https://bugzilla.redhat.com/show_bug.cgi?id=695568 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=695568 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/65542 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/65542 -
References () https://github.com/sitaramc/gitolite/commit/4ce00aef84d1ff7c35f7adbbb99a6241cfda00cc - Patch () https://github.com/sitaramc/gitolite/commit/4ce00aef84d1ff7c35f7adbbb99a6241cfda00cc - Patch

Information

Published : 2011-10-04 10:55

Updated : 2024-11-21 01:26


NVD link : CVE-2011-1572

Mitre link : CVE-2011-1572

CVE.ORG link : CVE-2011-1572


JSON object : View

Products Affected

gitolite

  • gitolite
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')