Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2013-4489
Disclosure Date: May 17, 2014 (last updated October 05, 2023)
The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as demonstrated by the search box for the GitLab code search feature.
0
Attacker Value
Unknown
CVE-2013-4546
Disclosure Date: May 13, 2014 (last updated October 05, 2023)
The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.
0
Attacker Value
Unknown
CVE-2013-4490
Disclosure Date: May 13, 2014 (last updated October 05, 2023)
The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.
0
Attacker Value
Unknown
CVE-2013-4581
Disclosure Date: May 12, 2014 (last updated October 05, 2023)
GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.
0
Attacker Value
Unknown
CVE-2013-4580
Disclosure Date: May 12, 2014 (last updated October 05, 2023)
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.
0