CVE-2013-4546
published 2014-05-13CVE-2013-4546: The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import…
PriorityP335medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.54%
72.0th percentile
The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab-shell | <= 1.7.3 | — |
| gitlab | gitlab-shell | — | — |
| gitlab | gitlab-shell | — | — |
| gitlab | gitlab-shell | — | — |
| gitlab | gitlab-shell | — | — |
| gitlab | gitlab-shell | — | — |
| gitlab | gitlab-shell | — | — |
| gitlab | gitlab-shell | — | — |
| gitlab | gitlab-shell | — | — |
| gitlab | gitlab-shell | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
CVE-2013-4546: The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the
vendor_gitlab·2014-05-13·CVSS 6.5
CVE-2013-4546 [MEDIUM] CVE-2013-4546: The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the
CVE-2013-4546: The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.
Debian
CVE-2013-4546: gitlab - The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, a...
vendor_debian·2013·CVSS 6.5
CVE-2013-4546 [MEDIUM] CVE-2013-4546: gitlab - The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, a...
The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.
Scope: local
sid: resolved
GHSA
GHSA-x3fv-8jf3-r4h2: The repository import feature in gitlab-shell before 1
ghsa_unreviewed·2022-05-17
CVE-2013-4546 [MEDIUM] GHSA-x3fv-8jf3-r4h2: The repository import feature in gitlab-shell before 1
The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2013/11/11/2https://gitlab.com/gitlab-org/gitlab-shell/blob/master/CHANGELOGhttps://www.gitlab.com/2013/11/08/security-vulnerability-in-gitlab-shell/http://www.openwall.com/lists/oss-security/2013/11/11/2https://gitlab.com/gitlab-org/gitlab-shell/blob/master/CHANGELOGhttps://www.gitlab.com/2013/11/08/security-vulnerability-in-gitlab-shell/
2014-05-13
Published