[3.7] gitolite: security issue in optional bundle helper ("rsync" command) (CVE-2018-20683)
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync,
mishandles the rsync command line, which allows
attackers to have a “bad” impact by triggering use of an option other than -v, -n, -q, or -P.
(from redmine: issue id 9886, created on 2019-01-21, closed on 2019-01-24)
- parent #9883 (closed)
- Revision fe8fcf4a by Natanael Copa on 2019-01-23T19:42:39Z:
main/gitolite: security upgrade to 3.6.11 (CVE-2018-20683) fixes #9886