1
0
mirror of https://git.FreeBSD.org/ports.git synced 2025-01-18 08:02:48 +00:00

Document gitlab-ce vulnerabilities.

This commit is contained in:
Matthias Fechner 2021-04-06 10:01:32 +02:00
parent 1532b5be37
commit b1a2d52166
2 changed files with 180329 additions and 0 deletions

180293
security/vuxml/vuln-flat.xml Normal file

File diff suppressed because it is too large Load Diff

View File

@ -78,6 +78,42 @@ Notes:
* Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
<vuln vid="56abf87b-96ad-11eb-a218-001b217b3468">
<topic>Gitlab -- Multiple vulnerabilities</topic>
<affects>
<package>
<name>gitlab-ce</name>
<range><ge>13.10.0</ge><lt>13.10.1</lt></range>
<range><ge>13.9.0</ge><lt>13.9.5</lt></range>
<range><ge>9</ge><lt>13.8.7</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>Gitlab reports:</p>
<blockquote cite="https://about.gitlab.com/releases/2021/03/31/security-release-gitlab-13-10-1-released/">
<p>Arbitrary File Read During Project Import</p>
<p>Kroki Arbitrary File Read/Write</p>
<p>Stored Cross-Site-Scripting in merge requests</p>
<p>Access data of an internal project through a public project fork as an anonymous user</p>
<p>Incident metric images can be deleted by any user</p>
<p>Infinite Loop When a User Access a Merge Request</p>
<p>Stored XSS in scoped labels</p>
<p>Admin CSRF in System Hooks Execution Through API</p>
<p>Update OpenSSL dependency</p>
<p>Update PostgreSQL dependency</p>
</blockquote>
</body>
</description>
<references>
<url>https://about.gitlab.com/releases/2021/03/31/security-release-gitlab-13-10-1-released/</url>
</references>
<dates>
<discovery>2021-03-31</discovery>
<entry>2021-04-06</entry>
</dates>
</vuln>
<vuln vid="1f6d97da-8f72-11eb-b3f1-005056a311d1">
<topic>samba -- Multiple Vulnerabilities</topic>
<affects>