CVE-2014-5023

Publication date

2014-07-22 14:00:00

Family

mitre

State

PUBLISHED

Description

Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.