CVE-2013-4582: Inclusion of Functionality from Untrusted Control Sphere
(updated )
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.
References
Code Behaviors & Features
Detect and mitigate CVE-2013-4582 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →