CVE-2013-4580: Medium severity GitLab GitLab vulnerability
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4580?
CVE-2013-4580 has been classified with a critical severity due to its potential to allow unauthorized user impersonation.
How do I fix CVE-2013-4580?
To fix CVE-2013-4580, upgrade GitLab to version 5.4.2 or later for all affected editions.
Which versions are affected by CVE-2013-4580?
CVE-2013-4580 affects GitLab versions earlier than 5.4.2 in the Community Edition and versions earlier than 6.2.1 in the Enterprise Edition.
What type of vulnerability is CVE-2013-4580?
CVE-2013-4580 is an authentication bypass vulnerability that affects MySQL backend configurations in GitLab.
Can CVE-2013-4580 be exploited remotely?
Yes, CVE-2013-4580 allows remote attackers to impersonate arbitrary users through unspecified API calls.