← Back

CVE-2013-4546

nvd nist
Published: May 13, 2014Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.

Affected (24)

2 products
Gitlab
Gitlab Shell
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
Version 5.0.0
Version 5.0.1
Version 5.1.0
Version 5.2.0
Version 5.3.0
Version 5.4.0
Version 5.4.1
Version 5.4.2
Version 6.0.0
Version 6.1.0
Version 6.2.0
Version 6.2.1
Version 6.2.2
Gitlab
Up to 1.7.3
Version 1.0.4
Version 1.1.0
Version 1.2.0
Version 1.3.0
Version 1.4.0
Version 1.5.0
Version 1.6.0
Version 1.7.0
Version 1.7.1
Version 1.7.2

References (6)

Timeline

No history available yet.