CVE-2012-4506: Gitolite
Medium severity, CVSS 4.6. EPSS: 2.1% chance of exploitation in the next 30 days.
Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.
Affected products
- Gitolite Gitolite: version 3.0 only; version 3.02 only; version 3.03 only; version 3.04 only
- Sitaram Chamarty Gitolite: version 3.01 only
Published 2012-10-22. Last modified 2026-06-16.