vulnerability

FreeBSD: VID-4091069E-860B-11E9-A05F-001B217B3468 (CVE-2019-12430): Gitlab -- Multiple Vulnerabilities

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Jun 3, 2019
Added
Jun 3, 2019
Modified
Mar 12, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-4091069E-860B-11E9-A05F-001B217B3468:




Gitlab reports:



Remote Command Execution Vulnerability on Repository Download Feature


Confidential Issue Titles Revealed to Restricted Users on Unsubscribe


Disclosure of Milestone Metadata through the Search API


Private Project Discovery via Comment Links


Metadata of Confidential Issues Disclosed to Restricted Users


Mandatory External Authentication Provider Sign-In Restrictions Bypass


Internal Projects Allowed to Be Created on in Private Groups


Server-Side Request Forgery Through DNS Rebinding


Stored Cross-Site Scripting on Wiki Pages


Stored Cross-Site Scripting on Notes


Repository Password Disclosed on Import Error Page


Protected Branches Restriction Rules Bypass


Stored Cross-Site Scripting Vulnerability on Child Epics




Solution

freebsd-upgrade-package-gitlab-ce
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.