DescriptionGitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs908699

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gitolite3 (PTS)jessie3.6.1-2+deb8u2vulnerable
buster, sid3.6.11-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs


[stretch] - gitolite3 <no-dsa> (Minor issue)
[jessie] - gitolite3 <no-dsa> (Minor issue)!topic/gitolite-announce/WrwDTYdbfRg

