Lucene search

K
freebsdFreeBSDE6B994E2-2891-11ED-9BE7-454B1DD82C64
HistoryAug 30, 2022 - 12:00 a.m.

Gitlab -- multiple vulnerabilities

2022-08-3000:00:00
vuxml.freebsd.org
40
remote command execution
stored xss
content injection
length validation
denial of service
abusing api calls
http requests
regular expression
information disclosure
regex backtracking
repository content read
idor
brute force attack

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

0.028 Low

EPSS

Percentile

90.8%

Gitlab reports:

Remote Command Execution via GitHub import
Stored XSS via labels color
Content injection via Incidents Timeline description
Lack of length validation in Snippets leads to Denial of Service
Group IP allow-list not fully respected by the Package Registry
Abusing Gitaly.GetTreeEntries calls leads to denial of service
Arbitrary HTTP Requests Possible in .ipynb Notebook with Malicious Form Tags
Regular Expression Denial of Service via special crafted input
Information Disclosure via Arbitrary GFM references rendered in Incident Timeline Events
Regex backtracking through the Commit message field
Read repository content via LivePreview feature
Denial of Service via the Create branch API
Denial of Service via Issue preview
IDOR in Zentao integration leaked issue details
Brute force attack may guess a password even when 2FA is enabled

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgitlab-ce=Β 15.3.0UNKNOWN
FreeBSDanynoarchgitlab-ce<Β 15.3.2UNKNOWN

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

0.028 Low

EPSS

Percentile

90.8%