Lucene search

K
freebsdFreeBSD3A023570-91AB-11ED-8950-001B217B3468
HistoryJan 09, 2023 - 12:00 a.m.

Gitlab -- Multiple Vulnerabilities

2023-01-0900:00:00
vuxml.freebsd.org
15
gitlab
vulnerabilities
email forgery
dos attack
resource abuse
token leakage
cross-site scripting
access tokens
unix
security.

8.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

72.7%

Gitlab reports:

Race condition on gitlab.com enables verified email forgery and third-party account hijacking
DOS and high resource consumption of Prometheus server through abuse of Grafana integration proxy endpoint
Maintainer can leak sentry token by changing the configured URL
Maintainer can leak masked webhook secrets by changing target URL of the webhook
Cross-site scripting in wiki changes page affecting self-hosted instances running without strict CSP
Group access tokens continue to work after owner loses ability to revoke them
Users’ avatar disclosure by user ID in private GitLab instances
Arbitrary Protocol Redirection in GitLab Pages
Regex DoS due to device-detector parsing user agents
Regex DoS in the Submodule Url Parser

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgitlab-ce= 15.7.0UNKNOWN
FreeBSDanynoarchgitlab-ce< 15.7.2UNKNOWN

8.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

72.7%

Related for 3A023570-91AB-11ED-8950-001B217B3468