Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-A003B74F-D7B3-11EA-9DF1-001B217B3468 (CVE-2020-13281): Gitlab -- Multiple Vulnerabilities

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

FreeBSD: VID-A003B74F-D7B3-11EA-9DF1-001B217B3468 (CVE-2020-13281): Gitlab -- Multiple Vulnerabilities

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
Published
08/05/2020
Created
08/10/2020
Added
08/07/2020
Modified
10/20/2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.

From VID-A003B74F-D7B3-11EA-9DF1-001B217B3468:

Gitlab reports:

Arbitrary File Read when Moving an Issue

Memory Exhaustion via Excessive Logging of Invite Email Error

Denial of Service Through Project Import Feature

User Controlled Git Configuration Settings Resulting in SSRF

Stored XSS in Issue Reference Number Tooltip

Stored XSS in Issues List via Milestone Title

Improper Access Control After Group Transfer

Bypass Email Verification Required for OAuth Flow

Confusion When Using Hexadecimal Branch Names

Insufficient OAuth Revocation

Improper Access Control for Project Sharing

Stored XSS in Jobs Page

Improper Access Control of Applications Page

SSRF into Shared Runner

Update Kramdown Gem

Solution(s)

  • freebsd-upgrade-package-gitlab-ce

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;