GitLab Multiple Vulnerabilities
Last Update Date:
3 Feb 2020 10:27
Release Date:
3 Feb 2020
5024
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in GitLab, a remote attacker could exploit some of these vulnerabilities to trigger denial of service, cross-site scripting and bypass security restriction on the targeted system.
Impact
- Cross-Site Scripting
- Denial of Service
- Security Restriction Bypass
System / Technologies affected
- GitLab EE version 11.11 and later
Solutions
Before installation of the software, please visit the software vendor web-site for more details.
- The vendor has issued a fix:
https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/
Vulnerability Identifier
- CVE-2019-16779
- CVE-2019-16892
- CVE-2019-18978
- CVE-2020-6833
- CVE-2020-7966
- CVE-2020-7967
- CVE-2020-7968
- CVE-2020-7969
- CVE-2020-7971
- CVE-2020-7972
- CVE-2020-7973
- CVE-2020-7974
- CVE-2020-7976
- CVE-2020-7977
- CVE-2020-7978
- CVE-2020-7979
- CVE-2020-8114
Source
Related Link
Share with