QID 375612
Date Published: 2021-06-09
QID 375612: GitLab Multiple Security Vulnerabilities(gitlab- 13-12-2, 13-11-5, 13-10-5)
GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.
All versions since 7.10 allowed an attacker to leak an OAuth access.
All versions since 11.8 allow an attacker to create a recursive pipeline relationship and exhaust resources.
All versions before 13.12.2, 13.11.5, or 13.10.5 allows an attacker to cause uncontrolled resource consumption.
All versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allows the user to maintain limited access.
All versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.
All versions since 9.5 allows a high privilege user to obtain sensitive information from log files.
All versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects.
All versions starting with 12.8 were affected by an issue in handling x509 certificates that could be used to spoof the author of signed commits.
Affected Versions:
All versions Before 13.12.2
All versions Before 13.11.5
All versions Before 13.10.5
QID Detection Logic:(Authenticated)
It fires GitLab-rake GitLab:env: info command to check the vulnerable version of GitLab.
Successful exploitation of these vulnerabilities allow sensitive data leak or DOS.
CVEs related to QID 375612
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Release |
|