CVE-2018-20683: Gitolite
High severity, CVSS 8.1. EPSS: 2% chance of exploitation in the next 30 days.
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.
Affected products
- Gitolite Gitolite: before 3.6.11 (fixed in 3.6.11)
Published 2019-01-10. Last modified 2026-06-17.