CVE-2013-4582: Inclusion of Functionality from Untrusted Control Sphere
(updated )
The (1) create_branch
, (2) create_tag
, (3) import_project
, and (4) fork_project
functions in lib/gitlab_projects.rb
allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.
References
Detect and mitigate CVE-2013-4582 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →