CVE-2013-4546: Medium severity GitLab GitLab vulnerability
Published May 13, 2014
·Updated
The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.
Affected Software
24 affected components
GitLab GitLab=5.0.0
GitLab GitLab=5.0.1
GitLab GitLab=5.1.0
GitLab GitLab=5.2.0
GitLab GitLab=5.3.0
GitLab GitLab=5.4.0
GitLab GitLab=5.4.1
GitLab GitLab=5.4.2
GitLab GitLab=6.0.0
GitLab GitLab=6.1.0
GitLab GitLab=6.2.0
GitLab GitLab=6.2.1
GitLab GitLab=6.2.2
GitLab gitlab-shell<=1.7.3
GitLab gitlab-shell=1.0.4
GitLab gitlab-shell=1.1.0
GitLab gitlab-shell=1.2.0
GitLab gitlab-shell=1.3.0
GitLab gitlab-shell=1.4.0
GitLab gitlab-shell=1.5.0
GitLab gitlab-shell=1.6.0
GitLab gitlab-shell=1.7.0
GitLab gitlab-shell=1.7.1
GitLab gitlab-shell=1.7.2
Remediation
Event History
May 13, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What are the potential impacts of CVE-2013-4546?
The potential impacts of CVE-2013-4546 include unauthorized command execution on the server, which may lead to data loss or compromise.