Race condition in gitolite - CVE-2018-16976
Published: September 13, 2018 / Updated: July 17, 2020
gitolite
Detailed vulnerability description
The vulnerability allows a remote authenticated user to read and manipulate data.
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.