Lucene search

K
freebsdFreeBSD3CDE510A-7135-11ED-A28B-BFF032704F00
HistoryNov 30, 2022 - 12:00 a.m.

Gitlab -- Multiple Vulnerabilities

2022-11-3000:00:00
vuxml.freebsd.org
14
authorization header exposure
ip allow-list bypass
webhook token leaks
xss
ssrf
dos
nuget packages

9.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

56.6%

Gitlab reports:

DAST API scanner exposes Authorization headers in vulnerabilities
Group IP allow-list not fully respected by the Package Registry
Deploy keys and tokens may bypass External Authorization service if it is enabled
Repository import still allows to import 40 hexadecimal branches
Webhook secret tokens leaked in webhook logs
Maintainer can leak webhook secret token by changing the webhook URL
Cross-site scripting in Jira Integration affecting self-hosted instances without strict CSP
Release names visible in public projects despite release set as project members only
Sidekiq background job DoS by uploading malicious NuGet packages
SSRF in Web Terminal advertise_address

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgitlab-ce= 15.6.0UNKNOWN
FreeBSDanynoarchgitlab-ce< 15.6.1UNKNOWN

9.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

56.6%

Related for 3CDE510A-7135-11ED-A28B-BFF032704F00