← Back

CVE-2012-4506

nvd nist
Published: Oct 22, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.6
Vector
AV:N/AC:H/Au:S/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.

Affected (5)

1 product
Gitolite
Gitolite
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Gitolite
Version 3.02
Version 3.03
Version 3.04
Version 3.0
Version 3.01

References (14)

Timeline

No history available yet.