Lucene search

K
freebsdFreeBSD4FFCCCAE-E924-11ED-9C88-001B217B3468
HistoryMay 02, 2023 - 12:00 a.m.

Gitlab -- Multiple Vulnerabilities

2023-05-0200:00:00
vuxml.freebsd.org
7
privilege escalation
oidc
account takeover
open redirect
ip addresses
developer role
group ci/cd variables
file integrity
public projects
xss
content injection
authenticated users
email

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.018

Percentile

88.2%

Gitlab reports:

Privilege escalation for external users when OIDC is enabled under certain conditions
Account takeover through open redirect for Group SAML accounts
Users on banned IP addresses can still commit to projects
User with developer role (group) can modify Protected branches setting on imported project and leak group CI/CD variables
The Gitlab web interface does not guarantee file integrity when downloading source code or installation packages from a tag or from a release.
Banned group member continues to have access to the public projects of a public group with the access level as same as before the ban.
The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.
XSS and content injection and iframe injection when viewing raw files on iOS devices
Authenticated users can find other users by their private email

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgitlab-ce= 15.11.0UNKNOWN
FreeBSDanynoarchgitlab-ce< 15.11.1UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.018

Percentile

88.2%

Related for 4FFCCCAE-E924-11ED-9C88-001B217B3468