CVE-2013-4580: GitLab

Medium severity, CVSS 6.8. EPSS: 1.3% chance of exploitation in the next 30 days.

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

Affected products

  • GitLab GitLab: up to and including 5.4.1; version 0.8.0 only; version 0.9.1 only; version 0.9.4 only; version 0.9.6 only; version 1.0.0 only; …

Published 2014-05-12. Last modified 2026-06-16.