LiveActive security incident?Get immediate response
CVE Record

CVE-2018-16976: Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict acce...

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This issue can let an already valid Gitolite user see or access a repository they should not during a repository migration. The risk is limited to Gitolite before 3.6.9 and certain configurations using @all or regex rules, but exposure could matter if private source code is hosted there.

Executive priority

Treat this as a focused source-code exposure risk, not a broad remote compromise claim. Prioritize if Gitolite protects sensitive repositories or if migrations occurred under broad access rules.

Technical view

Gitolite before 3.6.9 mishandles access restrictions for repositories in a migration state when specific @all or regex configuration patterns are involved. Until all migration steps are complete, authorization may be broader than intended, allowing valid users unintended repository access.

Likely exposure

Exposure is most likely in organizations running Gitolite before 3.6.9, using @all or regex-based access controls, and performing repository migration workflows. The source bundle does not identify broader affected products or package versions.

Exploitation context

No source in the bundle indicates active exploitation, and CISA KEV is false. Abuse appears to require a legitimate Gitolite user plus a vulnerable configuration and migration timing condition.

Researcher notes

Evidence is limited: no CVSS, CWE, or detailed affected package matrix is included. The clearest constraints are Gitolite before 3.6.9, @all or regex configurations, migration state, and valid-user unintended access.

Mitigation direction

  • Upgrade Gitolite to 3.6.9 or later where supported.
  • Review vendor and distribution guidance before changing production Gitolite policy.
  • Complete repository migrations promptly and verify final access rules.
  • Avoid broad @all or regex rules during migration unless explicitly required.
  • Audit sensitive repositories for unintended reads during migration windows.

Validation and detection

  • Identify the deployed Gitolite version across all Git servers.
  • Review Gitolite configs for @all and regex-based repository rules.
  • Check whether any repositories are currently in migration workflows.
  • Verify intended access after every migration step completes.
  • Review access logs for unexpected valid-user repository activity.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-16976 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.