vulnerability

FreeBSD: VID-4EA507D1-9DA8-11E9-A759-001B217B3468 (CVE-2019-13006): Gitlab -- Multiple Vulnerabilities

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Jul 3, 2019
Added
Jul 3, 2019
Modified
Mar 12, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-4EA507D1-9DA8-11E9-A759-001B217B3468:




Gitlab reports:



Ability to Write a Note to a Private Snippet


Recent Pipeline Information Disclosed to Unauthorised Users


Resource Exhaustion Attack


Error Caused by Encoded Characters in Comments


Authorization Issues in GraphQL


Number of Merge Requests was Accessible


Enabling One of the Service Templates Could Cause Resource Depletion


Broken Access Control for the Content of Personal Snippets


Decoding Color Codes Caused Resource Depletion


Merge Request Template Name Disclosure


SSRF Vulnerability in Project GitHub Integration




Solution

freebsd-upgrade-package-gitlab-ce
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.