CVE-2013-4581: Code Injection
Published May 12, 2014
·Updated
GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.
Affected Software
111 affected components
GitLab GitLab<=6.2.3
GitLab GitLab=0.8.0
GitLab GitLab=0.9.1
GitLab GitLab=0.9.4
GitLab GitLab=0.9.6
GitLab GitLab=1.0.0
GitLab GitLab=1.0.1
GitLab GitLab=1.0.2
GitLab GitLab=1.1.0
GitLab GitLab=1.2.0
GitLab GitLab=1.2.1
GitLab GitLab=1.2.2
GitLab GitLab=2.0.0
GitLab GitLab=2.1.0
GitLab GitLab=2.2.0
GitLab GitLab=2.3.0
GitLab GitLab=2.3.1
GitLab GitLab=2.4.0
GitLab GitLab=2.5.0
GitLab GitLab=2.6.0
GitLab GitLab=2.7.0
GitLab GitLab=2.8.0
GitLab GitLab=2.8.1
GitLab GitLab=2.9.0
GitLab GitLab=2.9.1
GitLab GitLab=3.0.0
GitLab GitLab=3.0.1
GitLab GitLab=3.0.2
GitLab GitLab=3.0.3
GitLab GitLab=3.1.0
GitLab GitLab=4.0.0
GitLab GitLab=4.1.0
GitLab GitLab=4.2.0
GitLab GitLab=5.0.0
GitLab GitLab=5.0.1
GitLab GitLab=5.1.0
GitLab GitLab=5.2.0
GitLab GitLab=5.3.0
GitLab GitLab=5.4.0
GitLab GitLab=5.4.1
GitLab GitLab=5.4.2
GitLab GitLab=6.0.0
GitLab GitLab=6.1.0
GitLab GitLab=6.2.0
GitLab GitLab=6.2.1
GitLab GitLab=6.2.2
GitLab GitLab<=6.2.0
GitLab GitLab=0.8.0
GitLab GitLab=0.9.1
GitLab GitLab=0.9.4
GitLab GitLab=0.9.6
GitLab GitLab=1.0.0
GitLab GitLab=1.0.1
GitLab GitLab=1.0.2
GitLab GitLab=1.1.0
GitLab GitLab=1.2.0
GitLab GitLab=1.2.1
GitLab GitLab=1.2.2
GitLab GitLab=2.0.0
GitLab GitLab=2.1.0
GitLab GitLab=2.2.0
GitLab GitLab=2.3.0
GitLab GitLab=2.3.1
GitLab GitLab=2.4.0
GitLab GitLab=2.5.0
GitLab GitLab=2.6.0
GitLab GitLab=2.7.0
GitLab GitLab=2.8.0
GitLab GitLab=2.8.1
GitLab GitLab=2.9.0
GitLab GitLab=2.9.1
GitLab GitLab=3.0.0
GitLab GitLab=3.0.1
GitLab GitLab=3.0.2
GitLab GitLab=3.0.3
GitLab GitLab=3.1.0
GitLab GitLab=4.0.0
GitLab GitLab=4.1.0
GitLab GitLab=4.2.0
GitLab GitLab=5.0.0
GitLab GitLab=5.0.1
GitLab GitLab=5.1.0
GitLab GitLab=5.2.0
GitLab GitLab=5.3.0
GitLab GitLab=5.4.0
GitLab GitLab=5.4.1
GitLab GitLab=5.4.2
GitLab GitLab=6.0.0
GitLab GitLab=6.1.0
GitLab gitlab-shell<=1.7.7
GitLab gitlab-shell=1.0.4
GitLab gitlab-shell=1.1.0
GitLab gitlab-shell=1.2.0
GitLab gitlab-shell=1.3.0
GitLab gitlab-shell=1.4.0
GitLab gitlab-shell=1.5.0
GitLab gitlab-shell=1.6.0
GitLab gitlab-shell=1.7.0
GitLab gitlab-shell=1.7.1
GitLab gitlab-shell=1.7.2
GitLab gitlab-shell=1.7.3
GitLab gitlab-shell=1.7.4
GitLab gitlab-shell=1.7.5
GitLab gitlab-shell=1.7.6
GitLab GitLab=5.0.0
GitLab GitLab=5.0.1
GitLab GitLab=5.1.0
GitLab GitLab=5.2.0
GitLab GitLab=5.3.0
GitLab GitLab=5.4.0
GitLab GitLab=5.4.1
Remediation
Event History
May 12, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4581?
CVE-2013-4581 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2013-4581?
To fix CVE-2013-4581, upgrade GitLab to version 5.4.2 or later for Community Editions and 6.2.1 or later for Enterprise Editions.
3
What versions of GitLab are affected by CVE-2013-4581?
CVE-2013-4581 affects GitLab versions prior to 5.4.2 for Community Edition and prior to 6.2.1 for Enterprise Edition.
4
Can CVE-2013-4581 be exploited without authentication?
Yes, CVE-2013-4581 can be exploited by remote attackers, making it a serious security risk.
5
What component is primarily affected by CVE-2013-4581?
CVE-2013-4581 primarily affects the GitLab application through its SSH functionality.