Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.
References
Link | Resource |
---|---|
http://hatriot.github.io/blog/2014/06/29/gitlist-rce/ | Exploit |
Configurations
History
No history.
Information
Published : 2014-07-22 14:55
Updated : 2024-02-04 18:35
NVD link : CVE-2014-5023
Mitre link : CVE-2014-5023
CVE.ORG link : CVE-2014-5023
JSON object : View
Products Affected
gitlist
- gitlist
CWE