Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ethan Strike

#20170of 53,635
12.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2019-14350
7.5
2019-09-16
Gitlab · Gitlab Ce/Ee · CVE-2019-15728
**Name of the Vulnerable Software and Affected Versions** GitLab Community and Enterprise Edition versions 10.1 through 12.2.1 **Description** An issue was discovered where protections against SSRF attacks on the Kubernetes integration are insufficient. This could have allowed an attacker to request any local network resource accessible from the GitLab server. **Recommendations** For GitLab Community and Enterprise Edition versions 10.1 through 12.2.1, consider restricting access to the Kubernetes integration until a patch is available. As a temporary workaround, limit the exposure of local network resources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2019-14359
5.3
2019-09-16
Gitlab · Gitlab Ce/Ee · CVE-2019-15738
**Name of the Vulnerable Software and Affected Versions** GitLab Community and Enterprise Edition versions 12.0 through 12.2.1 **Description** An issue was discovered where merge request IDs were being disclosed via email under certain conditions. **Recommendations** For GitLab Community and Enterprise Edition versions 12.0 through 12.2.1, update to a version that contains a fix for this issue to prevent merge request IDs from being disclosed via email.