vulnerability

FreeBSD: VID-c5bd9068-440f-11ea-9cdb-001b217b3468 (CVE-2019-16892): Gitlab -- Multiple Vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
Published
Jan 31, 2020
Added
Feb 1, 2020
Modified
Mar 25, 2026

Description

Gitlab reports: Path Traversal to Arbitrary File Read User Permissions Not Validated in ProjectExportWorker XSS Vulnerability in File API Package and File Disclosure through GitLab Workhorse XSS Vulnerability in Create Groups Issue and Merge Request Activity Counts Exposed Email Confirmation Bypass Using AP Disclosure of Forked Private Project Source Code Private Project Names Exposed in GraphQL queries Disclosure of Issues and Merge Requests via Todos Denial of Service via AsciiDoc Last Pipeline Status Exposed Arbitrary Change of Pipeline Status Grafana Token Displayed in Plaintext Update excon gem Update rdoc gem Update rack-cors gem Update rubyzip gem

Solution

freebsd-upgrade-package-gitlab-ce
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.