CVE-2013-4580 — Improper Authentication in Gitlab
Severity
6.8MEDIUMNVD
EPSS
0.1%
top 79.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 12
Latest updateMay 17
Description
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages3 packages
Patches
🔴Vulnerability Details
1📋Vendor Advisories
2GitLab▶
CVE-2013-4580: GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to imper↗2014-05-12
Debian▶
CVE-2013-4580: gitlab - GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition befo...↗2013