Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
GitLab heeft kwetsbaarheden verholpen in Enterprise Edition (EE) en Community Edition (CE).
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, of om zich verhoogde rechten toe te kennen en acties uit te voeren in de context van een andere gebruiker, waaronder ook mogelijk gebruikers met administrator-rechten.
- Oplossingen
GitLab heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
medium
- CWE-267
Privilege Defined With Unsafe Actions
- CWE-840
CWE-840
- CWE-424
Improper Protection of Alternate Path
- CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
- CWE-270
Privilege Context Switching Error
- CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
- CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-532
Insertion of Sensitive Information into Log File
- CWE-290
Authentication Bypass by Spoofing
- CWE-862
Missing Authorization
- CWE-1333
Inefficient Regular Expression Complexity
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-863
Incorrect Authorization
- CWE-209
Generation of Error Message Containing Sensitive Information
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard