Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.704206
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 4206-1 (gitlab - security update)
Zusammenfassung:Several vulnerabilities have been discovered in Gitlab, a software;platform to collaborate on code:;;CVE-2017-0920;It was discovered that missing validation of merge requests allowed;users to see names to private projects, resulting in information;disclosure.;;CVE-2018-8971;It was discovered that the Auth0 integration was implemented;incorrectly.
Beschreibung:Summary:
Several vulnerabilities have been discovered in Gitlab, a software
platform to collaborate on code:

CVE-2017-0920
It was discovered that missing validation of merge requests allowed
users to see names to private projects, resulting in information
disclosure.

CVE-2018-8971
It was discovered that the Auth0 integration was implemented
incorrectly.

Affected Software/OS:
gitlab on Debian Linux

Solution:
For the stable distribution (stretch), these problems have been fixed in
version 8.13.11+dfsg1-8+deb9u2. The fix for CVE-2018-8971
also requires ruby-omniauth-auth0 to be upgraded
to version 2.0.0-0+deb9u1.

We recommend that you upgrade your gitlab packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-0920
Debian Security Information: DSA-4206 (Google Search)
https://www.debian.org/security/2018/dsa-4206
https://hackerone.com/reports/301336
Common Vulnerability Exposure (CVE) ID: CVE-2018-8971
https://about.gitlab.com/2018/03/20/critical-security-release-gitlab-10-dot-5-dot-6-released/
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.