vulnerability
FreeBSD: VID-8A4ABA2D-F33E-11E8-9416-001B217B3468 (CVE-2018-19573): Gitlab -- Multiple vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:M/Au:S/C:N/I:P/A:N) | 2018-11-28 | 2018-11-29 | 2019-07-15 |
Description
Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.
From VID-8A4ABA2D-F33E-11E8-9416-001B217B3468:
Gitlab reports:
View Names of Private Groups
Persistent XSS in Environments
SSRF in Prometheus integration
Unauthorized Promotion of Milestones
Exposure of Confidential Issue Title
Persisent XSS in Markdown Fields via Mermaid Script
Persistent XSS in Markdown Fields via Unrecognized HTML Tags
Symlink Race Condition in Pages
Unauthorized Changes by Guest User in Issues
Unauthorized Comments on Locked Issues
Improper Enforcement of Token Scope
CRLF Injection in Project Mirroring
XSS in OAuth Authorization
SSRF in Webhooks
Send Email on Email Address Change
Workhorse Logs Contained Tokens
Unauthorized Publishing of Draft Comments
Guest Can Set Weight of a New Issue
Disclosure of Private Group's Members and Milestones
Persisent XSS in Operations
Reporter Can View Operations Page
Solution
References

Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.