The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 prior to 5.4.2, Community Edition prior to 6.2.4, and Enterprise Edition prior to 6.2.1 and gitlab-shell prior to 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gitlab gitlab |
||
gitlab gitlab-shell |