FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- Multiple vulnerabilities

Affected packages
15.4.0 <= gitlab-ce < 15.4.1
15.3.0 <= gitlab-ce < 15.3.4
9.3.0 <= gitlab-ce < 15.2.5

Details

VuXML ID 04422df1-40d8-11ed-9be7-454b1dd82c64
Discovery 2022-09-29
Entry 2022-09-30

Gitlab reports:

Denial of Service via cloning an issue

Arbitrary PUT request as victim user through Sentry error list

Content injection via External Status Checks

Project maintainers can access Datadog API Key from logs

Unsafe serialization of Json data could lead to sensitive data leakage

Import bug allows importing of private local git repos

Maintainer can leak Github access tokens by changing integration URL (even after 15.2.1 patch)

Unauthorized users able to create issues in any project

Bypass group IP restriction on Dependency Proxy

Healthcheck endpoint allow list can be bypassed when accessed over HTTP in an HTTPS enabled system

Disclosure of Todo details to guest users

A user's primary email may be disclosed through group member events webhooks

Content manipulation due to branch/tag name confusion with the default branch name

Leakage of email addresses in WebHook logs

Specially crafted output makes job logs inaccessible

Enforce editing approval rules on project level

References

CVE Name CVE-2022-2882
CVE Name CVE-2022-2904
CVE Name CVE-2022-3018
CVE Name CVE-2022-3060
CVE Name CVE-2022-3066
CVE Name CVE-2022-3067
CVE Name CVE-2022-3279
CVE Name CVE-2022-3283
CVE Name CVE-2022-3285
CVE Name CVE-2022-3286
CVE Name CVE-2022-3288
CVE Name CVE-2022-3291
CVE Name CVE-2022-3293
CVE Name CVE-2022-3325
CVE Name CVE-2022-3330
CVE Name CVE-2022-3351
URL https://about.gitlab.com/releases/2022/09/29/security-release-gitlab-15-4-1-released/