← All CVEs

CVE-2013-4490

medium · 6.5

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

6.5
CVSS
42.1%
EPSS (exploit prob.)
99th
EPSS percentile
2014-05-13
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

VendorProductAffected versions
gitlabgitlab5.0.0
gitlabgitlab5.0.1
gitlabgitlab5.1.0
gitlabgitlab5.2.0
gitlabgitlab5.3.0
gitlabgitlab5.4.0
gitlabgitlab6.0.0
gitlabgitlab6.1.0
gitlabgitlab6.2.0
gitlabgitlab6.2.1
gitlabgitlab6.2.2
gitlabgitlab-shell<= 1.7.2
gitlabgitlab-shell1.0.4
gitlabgitlab-shell1.1.0
gitlabgitlab-shell1.2.0
gitlabgitlab-shell1.3.0
gitlabgitlab-shell1.4.0
gitlabgitlab-shell1.5.0
gitlabgitlab-shell1.6.0
gitlabgitlab-shell1.7.0
gitlabgitlab-shell1.7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-4490