Description
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.
Affected products
- gitlab / gitlab5.0 before 5.4.2 – 5.0 before 5.4.2
- gitlab / GitLab Community Editionbefore 6.2.4 – before 6.2.4
- gitlab / GitLab Enterprise Editionbefore 6.2.1 – before 6.2.1
- gitlab / gitlab-shellbefore 1.7.8 – before 1.7.8