Gitolite is a lightweight, widely embedded Git access-control system deployed across many organizations for repository authorization and administrative scripting, despite a narrow product footprint. Its vulnerability exposure skews toward critical-severity outcomes and concentrates in a single product around input validation, path traversal, race conditions, and information disclosure—weakness classes that reflect the challenges of parsing user input and managing concurrent access in a permission-enforcement layer. Defenders should track this vendor's releases closely given the privileged role of access-control systems in the Git infrastructure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitolite over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2447CRITICAL gitolite before 1.4.1 does not filter src/ or hooks/ from path names. | Nov 7, 2019 | 9.8 | 30 | NO | NO |
CVE-2013-4451CRITICAL gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.git | Sep 21, 2018 | 9.8 | 27 | NO | NO |
CVE-2018-20683HIGH commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an op | Jan 10, 2019 | 8.1 | 26 | NO | NO |
CVE-2018-16976HIGH Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the | Sep 12, 2018 | 8.1 | 25 | NO | NO |
CVE-2011-1572MEDIUM Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequ | Oct 4, 2011 | 6.8 | 22 | NO | NO |
CVE-2013-7203MEDIUM gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup. | Sep 21, 2018 | 5.5 | 21 | NO | NO |
CVE-2012-4506MEDIUM Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbi | Oct 22, 2012 | 4.6 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitolite.
Media articles that mention a CVE ID that affects a product developed by Gitolite — matched by CVE ID, not by vendor name.