| |
Vulnerability CVE-2013-4489
Published: 2014-05-17 Modified: 2014-05-18
Description: |
The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as demonstrated by the search box for the GitLab code search feature. |
See advisories in our WLB2 database: | Topic | Author | Date |
High |
| joernchen | 04.11.2013 |
Type:
CWE-Other
CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
6.5/10 |
6.4/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
https://www.gitlab.com/2013/11/04/gitlab-ce-6-2-and-5-4-security-release/
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|