QID 375864
Date Published: 2021-09-27
QID 375864: GitLab Arbitrary File Read Vulnerability (gitlab-13-12-9, 14-0-7, and 14-1-2)
GitLab is a web-based DevOps lifecycle tool that provides a Git repository manager providing wiki, issue-tracking and continuous integration and deployment pipeline features, using an open-source license, developed by GitLab Inc.
GitLab Community Edition and Enterprise Edition is vulnerable to arbitrary file read via design feature vulnerability.
Affected versions:
13.3.0-13.12.8
14.1.0-14.1.1
14.0.0-14.0.6
QID Detection Logic:(Authenticated)
The QID checks for vulnerable version of Gitlab using 'gitlab-rake gitlab:env:info' command.
Successful exploitation of the vulnerability allows an attacker to read arbitrary files on the server via specially crafted design.
Solution
Customers are advised to upgrade to 13.12.9, 14.0.7, and 14.1.2 versions. For more information please visit: GitLab 14.2.2 Security Release
Vendor References
- Gitlab Critical Security Release -
about.gitlab.com/releases/2021/08/31/security-release-gitlab-14-2-2-released/
CVEs related to QID 375864
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Gitlab Security Release |
|