Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Debian: DSA-4206-1 Critical CVE-2017-0920 GitLab Information Disclosure

debian
Calendar Grey May 21, 2018
Debian Logo
Enhance GitLab installations by updating packages to mitigate risks such as data leaks and compatibility errors within Debian systems.
Several vulnerabilities have been discovered in Gitlab, a software platform to collaborate on code: CVE-2017-0920

Summary

Several vulnerabilities have been discovered in Gitlab, a software
platform to collaborate on code:

CVE-2017-0920

It was discovered that missing validation of merge requests allowed
users to see names to private projects, resulting in information
disclosure.

CVE-2018-8971

It was discovered that the Auth0 integration was implemented
incorrectly.

For the stable distribution (stretch), these problems have been fixed in
version 8.13.11+dfsg1-8+deb9u2. The fix for CVE-2018-8971 also requires
ruby-omniauth-auth0 to be upgraded to version 2.0.0-0+deb9u1.

We recommend that you upgrade your gitlab packages.

For the detailed security status of gitlab please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/gitlab

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: gitlab
CVE ID: CVE-2017-0920 CVE-2018-8971

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here