Lucene search

K
freebsdFreeBSD4C8C2218-B120-11EE-90EC-001B217B3468
HistoryJan 11, 2024 - 12:00 a.m.

Gitlab -- vulnerabilities

2024-01-1100:00:00
vuxml.freebsd.org
15
gitlab
security
vulnerabilities
bypasses
account takeover
password reset
user interactions
slack
mattermost
integrations
slash commands
codeowners approval
workspaces
namespace
commit signature validation
headers.

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

7.1 High

AI Score

Confidence

Low

0.96 High

EPSS

Percentile

99.5%

Gitlab reports:

Account Takeover via Password Reset without user interactions
Attacker can abuse Slack/Mattermost integrations to execute slash commands as another user
Bypass CODEOWNERS approval removal
Workspaces able to be created under different root namespace
Commit signature validation ignores headers after signature

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgitlab-ce= 16.7.0UNKNOWN
FreeBSDanynoarchgitlab-ce< 16.7.2UNKNOWN

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

7.1 High

AI Score

Confidence

Low

0.96 High

EPSS

Percentile

99.5%