FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- Multiple Vulnerabilities

Affected packages
12.5.0 <= gitlab-ce < 12.5.1
12.4.0 <= gitlab-ce < 12.4.4
gitlab-ce < 12.3.7

Details

VuXML ID 1aa7a094-1147-11ea-b537-001b217b3468
Discovery 2019-11-27
Entry 2019-11-27

Gitlab reports:

Path traversal with potential remote code execution

Private objects exposed through project import

Disclosure of notes via Elasticsearch integration

Disclosure of comments via Elasticsearch integration

DNS Rebind SSRF in various chat notifications

Disclosure of vulnerability status in dependency list

Disclosure of commit count in Cycle Analytics

Exposure of related branch names

Tags pushes from blocked users

Branches and Commits exposed to Guest members via integration

IDOR when adding users to protected environments

Former project members able to access repository information

Unauthorized access to grafana metrics

Todos created for former project members

Update Mattermost dependency

Disclosure of AWS secret keys on certain Admin pages

Stored XSS in Group and User profile fields

Forked project information disclosed via Project API

Denial of Service in the issue and commit comment pages

Tokens stored in plaintext

References

CVE Name CVE-2019-19086
CVE Name CVE-2019-19087
CVE Name CVE-2019-19088
CVE Name CVE-2019-19254
CVE Name CVE-2019-19255
CVE Name CVE-2019-19256
CVE Name CVE-2019-19257
CVE Name CVE-2019-19258
CVE Name CVE-2019-19259
CVE Name CVE-2019-19260
CVE Name CVE-2019-19261
CVE Name CVE-2019-19262
CVE Name CVE-2019-19263
CVE Name CVE-2019-19309
CVE Name CVE-2019-19310
CVE Name CVE-2019-19311
CVE Name CVE-2019-19312
CVE Name CVE-2019-19313
CVE Name CVE-2019-19314
URL https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/