vulnerability
FreeBSD: VID-4091069E-860B-11E9-A05F-001B217B3468 (CVE-2019-12430): Gitlab -- Multiple Vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:L/Au:S/C:P/I:P/A:P) | Jun 3, 2019 | Jun 3, 2019 | Mar 12, 2020 |
Description
Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.
From VID-4091069E-860B-11E9-A05F-001B217B3468:
Gitlab reports:
Remote Command Execution Vulnerability on Repository Download Feature
Confidential Issue Titles Revealed to Restricted Users on Unsubscribe
Disclosure of Milestone Metadata through the Search API
Private Project Discovery via Comment Links
Metadata of Confidential Issues Disclosed to Restricted Users
Mandatory External Authentication Provider Sign-In Restrictions Bypass
Internal Projects Allowed to Be Created on in Private Groups
Server-Side Request Forgery Through DNS Rebinding
Stored Cross-Site Scripting on Wiki Pages
Stored Cross-Site Scripting on Notes
Repository Password Disclosed on Import Error Page
Protected Branches Restriction Rules Bypass
Stored Cross-Site Scripting Vulnerability on Child Epics
Solution
References

Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.