vulnerability

FreeBSD: VID-A3495E61-047F-11EB-86EA-001B217B3468 (CVE-2020-13327): Gitlab -- multiple vulnerabilities

Severity
6
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:P)
Published
Oct 1, 2020
Added
Oct 3, 2020
Modified
Nov 4, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-A3495E61-047F-11EB-86EA-001B217B3468:




Gitlab reports:



Potential Denial Of Service Via Update Release Links API


Insecure Storage of Session Key In Redis


Improper Access Expiration Date Validation


Cross-Site Scripting in Multiple Pages


Unauthorized Users Can View Custom Project Template


Cross-Site Scripting in SVG Image Preview


Incomplete Handling in Account Deletion


Insufficient Rate Limiting at Re-Sending Confirmation Email


Improper Type Check in GraphQL


To-dos Are Not Redacted When Membership Changes


Guest users can modify confidentiality attribute


Command injection on runner host


Insecure Runner Configuration in Kubernetes Environments




Solution

freebsd-upgrade-package-gitlab-ce
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.