gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitolite | Gitolite | 3.0 (including) | 3.5.3 (including) |