Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-418C172B-B96F-11E7-B627-D43D7E971A1B: GitLab -- multiple vulnerabilities

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

FreeBSD: VID-418C172B-B96F-11E7-B627-D43D7E971A1B: GitLab -- multiple vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
10/17/2017
Created
07/25/2018
Added
10/25/2017
Modified
10/25/2017

Description

GitLab reports:

Cross-Site Scripting (XSS) vulnerability in the Markdown sanitization

filter

Yasin Soliman via HackerOne reported a Cross-Site Scripting (XSS)

vulnerability in the GitLab markdown sanitization filter. The sanitization

filter was not properly stripping invalid characters from URL schemes and

was therefore vulnerable to persistent XSS attacks anywhere Markdown was

supported.

Cross-Site Scripting (XSS) vulnerability in search bar

Josh Unger reported a Cross-Site Scripting (XSS) vulnerability in the

issue search bar. Usernames were not being properly HTML escaped inside the

author filter would could allow arbitrary script execution.

Open redirect in repository git redirects

Eric Rafaloff via HackerOne reported that GitLab was vulnerable to an

open redirect vulnerability when redirecting requests for repository names

that include the git extension. GitLab was not properly removing dangerous

parameters from the params field before redirecting which could allow an

attacker to redirect users to arbitrary hosts.

Username changes could leave repositories behind

An internal code review discovered that a bug in the code that moves

repositories during a username change could potentially leave behind

projects, allowing an attacker who knows the previous username to

potentially steal the contents of repositories on instances that are not

configured with hashed namespaces.

Solution(s)

  • freebsd-upgrade-package-gitlab

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;