CVE-2013-4490: Medium severity GitLab GitLab vulnerability
Published May 13, 2014
·Updated
The SSH key upload feature (lib/gitlabkeys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.
Affected Software
21 affected components
GitLab GitLab=5.0.0
GitLab GitLab=5.0.1
GitLab GitLab=5.1.0
GitLab GitLab=5.2.0
GitLab GitLab=5.3.0
GitLab GitLab=5.4.0
GitLab GitLab=6.0.0
GitLab GitLab=6.1.0
GitLab GitLab=6.2.0
GitLab GitLab=6.2.1
GitLab GitLab=6.2.2
GitLab gitlab-shell<=1.7.2
GitLab gitlab-shell=1.0.4
GitLab gitlab-shell=1.1.0
GitLab gitlab-shell=1.2.0
GitLab gitlab-shell=1.3.0
GitLab gitlab-shell=1.4.0
GitLab gitlab-shell=1.5.0
GitLab gitlab-shell=1.6.0
GitLab gitlab-shell=1.7.0
GitLab gitlab-shell=1.7.1
Remediation
Event History
May 13, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4490?
CVE-2013-4490 has a CVSS score of 5.0, indicating a medium severity level.
2
How do I fix CVE-2013-4490?
To fix CVE-2013-4490, upgrade GitLab to a version later than 5.4.1 or 6.2.3.
3
Which versions of GitLab are affected by CVE-2013-4490?
CVE-2013-4490 affects GitLab versions 5.0 through 5.4.0 and 6.0 through 6.2.2.
4
Can remote authenticated users exploit CVE-2013-4490?
Yes, remote authenticated users can exploit CVE-2013-4490 to execute arbitrary commands through shell metacharacters in the SSH public key.
5
What feature is vulnerable in CVE-2013-4490?
The SSH key upload feature in gitlab-shell prior to version 1.7.3 is vulnerable in CVE-2013-4490.