Vulnerabilities > CVE-2018-19359 - Unspecified vulnerability in Gitlab

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
gitlab
nessus

Summary

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

Nessus

NASL familyFreeBSD Local Security Checks
NASL idFREEBSD_PKG_D889D32CECD911E89416001B217B3468.NASL
descriptionGitlab reports : Persistent XSS Autocompletion Unauthorized service template creation
last seen2020-06-01
modified2020-06-02
plugin id119058
published2018-11-21
reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/119058
titleFreeBSD : Gitlab -- Multiple vulnerabilities (d889d32c-ecd9-11e8-9416-001b217b3468)