CVE-2013-4451: Gitolite

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.

Affected products

  • Gitolite Gitolite: from 3.0, up to and including 3.5.3

Published 2018-09-21. Last modified 2026-06-16.