From ddf691df64ce12d2b147348bb3055eaa0235d426 Mon Sep 17 00:00:00 2001 From: Matthias Fechner Date: Tue, 1 Jun 2021 23:27:10 +0200 Subject: [PATCH] security/vuxml: Document gitlab vulnerabilities. --- security/vuxml/vuln.xml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index c65356edacb9..9f5b59c17c1b 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -76,6 +76,44 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + Gitlab -- Multiple Vulnerabilities + + + gitlab-ce + 13.12.013.12.2 + 13.11.013.11.5 + 7.10.013.10.5 + + + + +

Gitlab reports:

+
+

Stealing GitLab OAuth access tokens using XSLeaks in Safari

+

Denial of service through recursive triggered pipelines

+

Unauthenticated CI lint API may lead to information disclosure and SSRF

+

Server-side DoS through rendering crafted Markdown documents

+

Issue and merge request length limit is not being enforced

+

Insufficient Expired Password Validation

+

XSS in blob viewer of notebooks

+

Logging of Sensitive Information

+

On-call rotation information exposed when removing a member

+

Spoofing commit author for signed commits

+

Enable qsh verification for Atlassian Connect

+
+ +
+ + CVE-2021-22181 + https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/ + + + 2021-06-01 + 2021-06-01 + +
+ redis -- integer overflow