Gitlist is a lightweight, self-hosted Git repository viewer and browser that provides web-based access to Git repositories; its vulnerability footprint is concentrated in this single product and reflects its role as a web-facing interface to version-control data. The recurring weaknesses observed center on improper input validation, a characteristic concern for web applications handling user-supplied queries and parameters. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitlist over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000533CRITICAL klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as | Jun 26, 2018 | 9.8 | 83 | NO | YES |
CVE-2014-4511HIGH Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats | Jul 22, 2014 | 7.5 | 81 | NO | YES |
CVE-2013-7392HIGH Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/. | Jul 22, 2014 | 7.5 | 37 | NO | YES |
CVE-2014-5023MEDIUM Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrate | Jul 22, 2014 | 6.8 | 32 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitlist.
Media articles that mention a CVE ID that affects a product developed by Gitlist — matched by CVE ID, not by vendor name.