FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

nothing found there

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
1aa7a094-1147-11ea-b537-001b217b3468Gitlab -- Multiple Vulnerabilities

Gitlab reports:

Path traversal with potential remote code execution

Private objects exposed through project import

Disclosure of notes via Elasticsearch integration

Disclosure of comments via Elasticsearch integration

DNS Rebind SSRF in various chat notifications

Disclosure of vulnerability status in dependency list

Disclosure of commit count in Cycle Analytics

Exposure of related branch names

Tags pushes from blocked users

Branches and Commits exposed to Guest members via integration

IDOR when adding users to protected environments

Former project members able to access repository information

Unauthorized access to grafana metrics

Todos created for former project members

Update Mattermost dependency

Disclosure of AWS secret keys on certain Admin pages

Stored XSS in Group and User profile fields

Forked project information disclosed via Project API

Denial of Service in the issue and commit comment pages

Tokens stored in plaintext


Discovery 2019-11-27
Entry 2019-11-27
gitlab-ce
ge 12.5.0 lt 12.5.1

ge 12.4.0 lt 12.4.4

lt 12.3.7

https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/
CVE-2019-19088
CVE-2019-19309
CVE-2019-19086
CVE-2019-19087
CVE-2019-19261
CVE-2019-19256
CVE-2019-19254
CVE-2019-19257
CVE-2019-19263
CVE-2019-19258
CVE-2019-19259
CVE-2019-19260
CVE-2019-19262
CVE-2019-19255
CVE-2019-19310
CVE-2019-19311
CVE-2019-19312
CVE-2019-19313
CVE-2019-19314