Security Advisory
CVE-2013-4546
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.