QID 375522
Date Published: 2021-05-06
QID 375522: GitLab Multiple Security Vulnerabilities(gitlab- 13-11-2, 13-10-4, 13-9-7)
GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.
All versions starting with 13.8: Read API scoped tokens can execute mutations
All versions starting with 11.6: Pull mirror credentials were exposed
All versions starting with 13.2: Denial of Service when querying repository branches API
All versions prior to 13.5: Non-owners can set system_note_timestamp when creating / updating issues
All versions starting from 13.7: DeployToken will impersonate a User with the same ID when using Dependency Proxy
Affected Versions:
All version starting with 13.8
All versions starting with 11.6
All versions starting with 13.2
All versions prior to 13.5
All versions of Gitlab EE/CE starting with 13.7
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of these vulnerabilities allow sensitive data leak or DOS.
CVEs related to QID 375522
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Release |
|