← Back

CVE-2013-4489

nvd nist
Published: May 17, 2014Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as demonstrated by the search box for the GitLab code search feature.

Affected (8)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
Version 5.2.0
Version 5.3.0
Version 5.4.0
Version 6.0.0
Version 6.1.0
Version 6.2.0
Version 6.2.1
Version 6.2.2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.