QID 376040
Date Published: 2021-11-22
QID 376040: GitLab Multiple Security Vulnerabilities (gitlab release-14.2.6,14.3.4,14.4.1)
GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.
GitLab is prone to:
CVE-2021-39897
CVE-2021-39898
CVE-2021-39902
CVE-2021-39903
CVE-2021-39904
CVE-2021-39906
CVE-2021-39907
CVE-2021-39909
CVE-2021-39912
CVE-2021-39914
CVE-2021-39908
CVE-2021-39895
CVE-2021-39905
CVE-2021-39913
CVE-2021-39901
CVE-2021-39911
Affected Version:
All versions Prior to 14.2.6
All versions Prior to 14.3.4
All versions Prior to 14.4.1
QID Detection Logic:(Authenticated)
It fires GitLab-rake GitLab:env: info command to check the vulnerable version of GitLab.
Successful exploitation of these vulnerabilities allow sensitive data leak, excessive usage of resources and improper access control.
Solution
The vendor has released patch, For more information please visit gitlab-13-12-2
Vendor References
CVEs related to QID 376040
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Release |
|