PoC Index

CVE-2013-4490

MEDIUM 6.5EPSS 42.1%

The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
42.14% chance of exploitation in the next 30 days, 99th percentile
Published
2014-05-13
Updated
2024-08-06

Metasploit modules (1)

ExploitDB entries (1)

References

Related