CVE-2013-4546 Information

Description

The repository import feature in gitlab-shell before 1.7.4 as used in GitLab allows remote authenticated users to execute arbitrary commands via the import URL.

Reference

http://www.openwall.com/lists/oss-security/2013/11/11/2 https://gitlab.com/gitlab-org/gitlab-shell/blob/master/CHANGELOG https://www.gitlab.com/2013/11/08/security-vulnerability-in-gitlab-shell/

Share on: