AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-4663

HIGH · CVSS 7.5 EPSS 1.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-12-28 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.

CVE
CVE-2013-4663
Severity
HIGH
CVSS
7.5
EPSS
1.94%

Original NVD Description

git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists function.