CVE-2012-4506: Gitolite

Medium severity, CVSS 4.6. EPSS: 2.1% chance of exploitation in the next 30 days.

Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.

Affected products

  • Gitolite Gitolite: version 3.0 only; version 3.02 only; version 3.03 only; version 3.04 only
  • Sitaram Chamarty Gitolite: version 3.01 only

Published 2012-10-22. Last modified 2026-06-16.