QID 375475

Date Published: 2021-04-22

QID 375475: GitLab Multiple Security Vulnerabilities(gitlab- 13-10-3)

GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.

All versions starting from 11.9.

Affected Versions:
All versions starting from 11.9. Affects versions 7.12 and later

QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.

On successful exploit the attacker may cause denial of service or unauthorized access on the affected target.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released patch, For more information please visit gitlab-13-10-3

    CVEs related to QID 375475

    Software Advisories
    Advisory ID Software Component Link
    GitLab Security Release URL Logo about.gitlab.com/releases/2021/04/14/security-release-gitlab-13-10-3-released/