gitolite: security issue in optional bundle helper ("rsync" command) (CVE-2018-20683)
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync,
mishandles the rsync command line, which allows
attackers to have a “bad” impact by triggering use of an option other
than -v, -n, -q, or -P.
References:
https://nvd.nist.gov/vuln/detail/CVE-2018-20683
https://github.com/sitaramc/gitolite/blob/master/CHANGELOG
Patch:
https://github.com/sitaramc/gitolite/commit/5df2b817255ee919991da6c310239e08c8fcc1ae
(from redmine: issue id 9883, created on 2019-01-21, closed on 2019-01-24)
- Relations:
- child #9884 (closed)
- child #9885 (closed)
- child #9886 (closed)
- child #9887 (closed)