Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
GitLab heeft kwetsbaarheden verholpen in versies 18.9.2, 18.8.6 en 18.7.6
- Interpretaties
De kwetsbaarheden omvatten verschillende problemen, waaronder onjuiste autorisatiecontroles die geauthenticeerde gebruikers in staat stelden om toegang te krijgen tot gevoelige gegevens, zoals metadata van private repositories, en het mogelijk maken van denial-of-service situaties door onjuiste invoervalidatie. Specifieke kwetsbaarheden betroffen de CI/CD-pijplijn, webhook-verwerking, en de importfunctionaliteit, waarbij ongepaste toegang tot API-gegevens en projectmetadata kon optreden. De kwetsbaarheden beïnvloeden de vertrouwelijkheid en beschikbaarheid van gegevens binnen GitLab.
- Oplossingen
GitLab heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
- CWE-116
Improper Encoding or Escaping of Output
- CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
- CWE-288
Authentication Bypass Using an Alternate Path or Channel
- CWE-674
Uncontrolled Recursion
- CWE-706
Use of Incorrectly-Resolved Name or Reference
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-862
Missing Authorization
- CWE-863
Incorrect Authorization
- CWE-1284
Improper Validation of Specified Quantity in Input
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard