PT-2017-10160 · Gitlab · Gitlab

Jobert

·

Publicado

2017-03-28

·

Atualizado

2019-10-09

·

CVE-2016-9469

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions GitLab versions 8.12.0 through 8.12.10 GitLab versions 8.13.0 through 8.13.7 GitLab versions 8.14.0 through 8.14.2
Description The issue exposes a dangerous method to any authenticated user, potentially leading to the deletion of all Issue and MergeRequest objects on a GitLab instance. For instances with publicly available projects, this could be exploited by an unauthenticated user.
Recommendations For GitLab versions 8.12.0 through 8.12.10, update to version 8.12.11. For GitLab versions 8.13.0 through 8.13.7, update to version 8.13.8. For GitLab versions 8.14.0 through 8.14.2, update to version 8.14.3.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9469

Produtos afetados

Gitlab