gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/149438/ManageEngine-SupportCenter-Plus-8.1.0-Cross-Site-Scripting.html | vdb entry third party advisory not applicable |
https://lists.fedoraproject.org/pipermail/package-announce/2014-January/125611.html | third party advisory vendor advisory |
https://marc.info/?l=oss-security&m=138783069700756&w=2 | third party advisory mailing list |