Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.
References
Link | Resource |
---|---|
http://hatriot.github.io/blog/2014/06/29/gitlist-rce/ | Exploit |
http://hatriot.github.io/blog/2014/06/29/gitlist-rce/ | Exploit |
Configurations
History
21 Nov 2024, 02:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://hatriot.github.io/blog/2014/06/29/gitlist-rce/ - Exploit |
Information
Published : 2014-07-22 14:55
Updated : 2025-04-12 10:46
NVD link : CVE-2014-5023
Mitre link : CVE-2014-5023
CVE.ORG link : CVE-2014-5023
JSON object : View
Products Affected
gitlist
- gitlist
CWE