vulnerability

FreeBSD: VID-8A4ABA2D-F33E-11E8-9416-001B217B3468 (CVE-2018-19573): Gitlab -- Multiple vulnerabilities

Severity
4
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
2018-11-28
Added
2018-11-29
Modified
2019-07-15

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-8A4ABA2D-F33E-11E8-9416-001B217B3468:




Gitlab reports:



View Names of Private Groups


Persistent XSS in Environments


SSRF in Prometheus integration


Unauthorized Promotion of Milestones


Exposure of Confidential Issue Title


Persisent XSS in Markdown Fields via Mermaid Script


Persistent XSS in Markdown Fields via Unrecognized HTML Tags


Symlink Race Condition in Pages


Unauthorized Changes by Guest User in Issues


Unauthorized Comments on Locked Issues


Improper Enforcement of Token Scope


CRLF Injection in Project Mirroring


XSS in OAuth Authorization


SSRF in Webhooks


Send Email on Email Address Change


Workhorse Logs Contained Tokens


Unauthorized Publishing of Draft Comments


Guest Can Set Weight of a New Issue


Disclosure of Private Group's Members and Milestones


Persisent XSS in Operations


Reporter Can View Operations Page




Solution

freebsd-upgrade-package-gitlab-ce
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.