Vulnerabilities > CVE-2018-17449 - Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | FreeBSD Local Security Checks |
NASL id | FREEBSD_PKG_065B3B72C5AB11E89AE2001B217B3468.NASL |
description | Gitlab reports : SSRF GCP access token disclosure Persistent XSS on issue details Diff formatter DoS in Sidekiq jobs Confidential information disclosure in events API endpoint validate_localhost function in url_blocker.rb could be bypassed Slack integration CSRF Oauth2 GRPC::Unknown logging token disclosure IDOR merge request approvals Persistent XSS package.json Persistent XSS merge request project import |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 117863 |
published | 2018-10-02 |
reporter | This script is Copyright (C) 2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/117863 |
title | FreeBSD : Gitlab -- multiple vulnerabilities (065b3b72-c5ab-11e8-9ae2-001b217b3468) |
code |
|