Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.
From VID-B68CC195-CAE7-11E9-86E9-001B217B3468:
Gitlab reports:
Kubernetes Integration Server-Side Request Forgery
Server-Side Request Forgery in Jira Integration
Improved Protection Against Credential Stuffing Attacks
Markdown Clientside Resource Exhaustion
Pipeline Status Disclosure
Group Runner Authorization Issue
CI Metrics Disclosure
User IP Disclosed by Embedded Image and Media
Label Description HTML Injection
IDOR in Epic Notes API
Push Rule Bypass
Project Visibility Restriction Bypass
Merge Request Discussion Restriction Bypass
Disclosure of Merge Request IDs
Weak Authentication In Certain Account Actions
Disclosure of Commit Title and Comments
Stored XSS via Markdown
EXIF Geolocation Data Exposure
Multiple SSRF Regressions on Gitaly
Default Branch Name Exposure
Potential Denial of Service via CI Pipelines
Privilege Escalation via Logrotate
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center