Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2023-5332
Disclosure Date: December 04, 2023 (last updated December 08, 2023)
Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.
0
Attacker Value
Unknown
CVE-2013-4546
Disclosure Date: May 13, 2014 (last updated October 05, 2023)
The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.
0
Attacker Value
Unknown
CVE-2013-4490
Disclosure Date: May 13, 2014 (last updated October 05, 2023)
The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.
0
Attacker Value
Unknown
CVE-2013-4581
Disclosure Date: May 12, 2014 (last updated October 05, 2023)
GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.
0
Attacker Value
Unknown
CVE-2013-4580
Disclosure Date: May 12, 2014 (last updated October 05, 2023)
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.
0