[3.8] gitolite: security issue in optional bundle helper ("rsync" command) (CVE-2018-20683)
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync,
mishandles the rsync command line, which allows
attackers to have a “bad” impact by triggering use of an option other than -v, -n, -q, or -P.
(from redmine: issue id 9885, created on 2019-01-21, closed on 2019-01-24)
- parent #9883 (closed)
- Revision bac73999 by Natanael Copa on 2019-01-23T19:40:38Z:
main/gitolite: security upgrade to 3.6.11 (CVE-2018-20683) fixes #9885