CVE-2013-4580Improper Authentication in Gitlab

Severity
6.8MEDIUMNVD
EPSS
0.1%
top 79.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 12
Latest updateMay 17

Description

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

NVDgitlab/gitlab5.4.1+47
debiandebian/gitlab
gitlabgitlab/gitlab

Patches

🔴Vulnerability Details

1
GHSA
GHSA-9q79-pqhq-v25q: GitLab before 52022-05-17

📋Vendor Advisories

2
GitLab
CVE-2013-4580: GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to imper2014-05-12
Debian
CVE-2013-4580: gitlab - GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition befo...2013