VULNERABILITY

FreeBSD: VID-1020D401-6D2D-11EB-AB0B-001B217B3468: Gitlab -- Multiple Vulnerabilities

Try Surface Command Get a continuous 360° view of your attack surface
Back to Search

FreeBSD: VID-1020D401-6D2D-11EB-AB0B-001B217B3468: Gitlab -- Multiple Vulnerabilities

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:N/A:C)
Published
02/11/2021
Created
02/17/2021
Added
02/13/2021
Modified
02/19/2025

Description

Gitlab reports:

Improper Certificate Validation for Fortinet OTP

Denial of Service Attack on gitlab-shell

Resource exhaustion due to pending jobs

Confidential issue titles were exposed

Improper access control allowed demoted project members to access authored merge requests

Improper access control allowed unauthorized users to access analytic pages

Unauthenticated CI lint API may lead to information disclosure and SSRF

Prometheus integration in Gitlab may lead to SSRF

Solution(s)

  • freebsd-upgrade-package-gitlab-ce

insightVM

Advanced vulnerability management analytics and reporting.
Key Features
  • Lightweight Endpoint Agent
  • Live Dashboards
  • Real Risk Prioritization
  • IT-Integrated Remediation Projects
  • Cloud, Virtual, and Container Assessment
  • Integrated Threat Feeds
  • Easy-to-Use RESTful API
  • Automation-Assisted Patching
  • Automated Containment
Free InsightVM Trial View All Features

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;