vulnerability

FreeBSD: VID-E8483115-8B8E-11EA-BDCF-001B217B3468 (CVE-2020-10187): Gitlab -- Multiple Vulnerabilities

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
2020-04-30
Added
2020-05-02
Modified
2020-10-20

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-E8483115-8B8E-11EA-BDCF-001B217B3468:




Gitlab reports:



Path Traversal in NuGet Package Registry


Workhorse Bypass Leads to File Disclosure


OAuth Application Client Secrets Revealed


Code Owners Approval Rules Are Not Updated for Existing Merge Requests When Source Branch Changes


Code Owners Protection Not Enforced from Web UI


Repository Mirror Passwords Exposed To Maintainers


Admin Audit Log Page Denial of Service


Private Project ID Revealed Through Group API


Elasticsearch Credentials Logged to ELK


GitHub Personal Access Token Exposed on Integrations Page


Update Nokogiri dependency


Update OpenSSL Dependency


Update git




Solution

freebsd-upgrade-package-gitlab-ce
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.