Vulnerabilities > CVE-2019-9178 - Unspecified vulnerability in Gitlab
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 4 of 5).
Vulnerable Configurations
Nessus
NASL family | FreeBSD Local Security Checks |
NASL id | FREEBSD_PKG_112924603F2F11E9ADCB001B217B3468.NASL |
description | Gitlab reports : Arbitrary file read via MergeRequestDiff CSRF add Kubernetes cluster integration Blind SSRF in prometheus integration Merge request information disclosure IDOR milestone name information disclosure Burndown chart information disclosure Private merge request titles in public project information disclosure Private namespace disclosure in email notification when issue is moved Milestone name disclosure Issue board name disclosure NPM automatic package referencer Path traversal snippet mover Information disclosure repo existence Issue DoS via Mermaid Privilege escalation impersonate user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 122630 |
published | 2019-03-06 |
reporter | This script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/122630 |
title | FreeBSD : Gitlab -- Multiple vulnerabilities (11292460-3f2f-11e9-adcb-001b217b3468) |
code |
|
References
- https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/
- https://about.gitlab.com/blog/categories/releases/
- https://gitlab.com/gitlab-org/gitlab-ce/issues/54803
- https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/
- https://gitlab.com/gitlab-org/gitlab-ce/issues/54803
- https://about.gitlab.com/blog/categories/releases/