Vendor
GitList version 2.0.0 contains an OS command injection vulnerability in the getDefaultBranch function, allowing unauthenticated remote attackers to execute arbitrary system commands.