commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.
https://github.com/sitaramc/gitolite/commit/5df2b817255ee919991da6c310239e08c8fcc1ae
https://github.com/sitaramc/gitolite/blob/master/CHANGELOG
https://bugs.debian.org/918849
https://groups.google.com/forum/#%21topic/gitolite-announce/6xbjjmpLePQ
Source: Mitre, NVD
Published: 2019-01-10
Updated: 2024-11-21
Base Score: 6.8
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P
Severity: Medium
Base Score: 8.1
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.0051