Lucene search

K
freebsdFreeBSD01BDE18A-2E09-11EA-A935-001B217B3468
HistoryJan 02, 2020 - 12:00 a.m.

Gitlab -- Multiple Vulnerabilities

2020-01-0200:00:00
vuxml.freebsd.org
13

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

40.9%

SO-AND-SO reports:

Group Maintainers Can Update/Delete Group Runners Using API
GraphQL Queries Can Hang the Application
Unauthorized Users Have Access to Milestones of Releases
Private Group Name Revealed Through Protected Tags API
Users Can Publish Reviews on Locked Merge Requests
DoS in the Issue and Commit Comments Pages
Project Name Disclosed Through Unsubscribe Link
Private Project Name Disclosed Through Notification Settings

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgitlab-ce= 12.6.0UNKNOWN
FreeBSDanynoarchgitlab-ce< 12.6.2UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

40.9%

Related for 01BDE18A-2E09-11EA-A935-001B217B3468