Gitlab -- Multiple Vulnerabilities

Affected packages
12.7.0 <= gitlab-ce < 12.7.4
12.6.0 <= gitlab-ce < 12.6.6
5.3 <= gitlab-ce < 12.5.9


VuXML ID c5bd9068-440f-11ea-9cdb-001b217b3468
Discovery 2020-01-30
Entry 2020-01-31

Gitlab reports:

Path Traversal to Arbitrary File Read

User Permissions Not Validated in ProjectExportWorker

XSS Vulnerability in File API

Package and File Disclosure through GitLab Workhorse

XSS Vulnerability in Create Groups

Issue and Merge Request Activity Counts Exposed

Email Confirmation Bypass Using AP

Disclosure of Forked Private Project Source Code

Private Project Names Exposed in GraphQL queries

Disclosure of Issues and Merge Requests via Todos

Denial of Service via AsciiDoc

Last Pipeline Status Exposed

Arbitrary Change of Pipeline Status

Grafana Token Displayed in Plaintext

Update excon gem

Update rdoc gem

Update rack-cors gem

Update rubyzip gem


