GitLab Multiple Vulnerabilities
Release Date:
7 Feb 2022
5124
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, security restriction bypass, spoofing and cross-site scripting on the targeted system.
Impact
- Denial of Service
- Information Disclosure
- Security Restriction Bypass
- Spoofing
- Cross-Site Scripting
System / Technologies affected
- GitLab Community Edition (CE) versions prior to 14.7.1, 14.6.4, and 14.5.4
GitLab Enterprise Edition (EE) versions prior to 14.7.1, 14.6.4, and 14.5.4
GitLab Omnibus prior to 14.7
Solutions
Before installation of the software, please visit the software vendor web-site for more details.
- The vendor has issued a fix
https://about.gitlab.com/releases/2022/02/03/security-release-gitlab-14-7-1-released/
Vulnerability Identifier
- CVE-2021-39931
- CVE-2021-39943
- CVE-2022-0123
- CVE-2022-0136
- CVE-2022-0167
- CVE-2022-0249
- CVE-2022-0283
- CVE-2022-0344
- CVE-2022-0371
- CVE-2022-0373
- CVE-2022-0390
- CVE-2022-0425
- CVE-2022-0427
- CVE-2022-0477
- CVE-2022-0488
Source
Related Link
Related Tags
Share with