Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0373

Published Sep 13, 2024·Last modified Sep 13, 2024
Description
Feiten

GitLab heeft kwetsbaarheden verholpen in Enterprise Edition (EE) en Community Edition (CE).

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, of om zich verhoogde rechten toe te kennen en acties uit te voeren in de context van een andere gebruiker, waaronder ook mogelijk gebruikers met administrator-rechten.

Oplossingen

GitLab heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

medium

CWE-267

Privilege Defined With Unsafe Actions

CWE-840

CWE-840

CWE-424

Improper Protection of Alternate Path

CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

CWE-270

Privilege Context Switching Error

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-532

Insertion of Sensitive Information into Log File

CWE-290

Authentication Bypass by Spoofing

CWE-862

Missing Authorization

CWE-1333

Inefficient Regular Expression Complexity

CWE-918

Server-Side Request Forgery (SSRF)

CWE-863

Incorrect Authorization

CWE-209

Generation of Error Message Containing Sensitive Information

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard