[FREEBSD:DA459DBC-5586-11E9-ABD6-001B217B3468] Gitlab -- Multiple vulnerabilities

Severity High
Affected Packages 1
CVEs 12

Gitlab reports:

  DoS potential for regex in CI/CD refs
  Related branches visible in issues for guests
  Persistent XSS at merge request resolve conflicts
  Improper authorization control "move issue"
  Guest users of private projects have access to releases
  DoS potential on project languages page
  Recurity assessment: information exposure through timing discrepancy
  Recurity assessment: loginState HMAC issues
  Recurity assessment: open redirect
  PDF.js vulnerable to CVE-2018-5158
  IDOR labels of private projects/groups
  EXIF geolocation data not stripped from uploaded images
Package Affected Version
pkg:freebsd/gitlab-ce < 11.9.4
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/gitlab-ce gitlab-ce < 11.9.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...