Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
198

Arch Linux ASA-202106-21 High Severity: GitLab Multiple Issues Advisory

The package gitlab before version 13.12.2-1 is vulnerable to multiple issues including denial of service, information disclosure, access restriction bypass, authentication bypass, cross-site scripting and content spoofing. . Arch Linux Security Advisory ASA-202106-21 ========================================= Severity: High Date : 2021-06-09 CVE-ID : CVE-2021-22181 CVE-2021-22213 CVE-2021-22214 CVE-2021-22216 CVE-2021-22217 CVE-2021-22218 CVE-2021-22219 CVE-2021-22220 CVE-2021-22221 Package : gitlab Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2023 Summary ====== The package gitlab before version 13.12.2-1 is vulnerable to multiple issues including denial of service, information disclosure, access restriction bypass, authentication bypass, cross-site scripting and content spoofing. Resolution ========= Upgrade to 13.12.2-1. # pacman -Syu "gitlab> =13.12.2-1" The problems have been fixed upstream in version 13.12.2. Workaround ========= None. Description ========== - CVE-2021-22181 (denial of service) A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 before 13.12.2 allows an attacker to create a recursive pipeline relationship and exhaust resources. - CVE-2021-22213 (information disclosure) A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 before 13.12.2 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari. - CVE-2021-22214 (access restriction bypass) When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 before 13.12.2 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited. - CVE-2021-22216 (denial of service) A denial of service vulnerability in all versions of GitLab CE/EE before13.12.2 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description. - CVE-2021-22217 (denial of service) A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request. - CVE-2021-22218 (content spoofing) All versions of GitLab CE/EE starting with 12.8 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits. - CVE-2021-22219 (information disclosure) GitLab CE/EE since version 9.5 before 13.12.2 allows a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking. - CVE-2021-22220 (cross-site scripting) An issue has been discovered in GitLab affecting all versions starting with 13.10 before 13.12.2. GitLab was vulnerable to a stored cross-site scripting (XSS) attack in the blob viewer of notebooks. - CVE-2021-22221 (authentication bypass) An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.12.2. Insufficient expired password validation in various operations allowed users to maintain limited access after their password expired. Impact ===== A remote attacker could disclose sensitive information, bypass authentication, execute JavaScript code using cross-site scripting, spoof content or crash the GitLabserver. References ========= https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/ https://gitlab.com/gitlab-org/gitlab/-/issues/300308 https://gitlab.com/gitlab-org/gitlab/-/issues/300709 https://gitlab.com/gitlab-org/gitlab/-/issues/297665 https://gitlab.com/gitlab-org/gitlab/-/issues/294128 https://security.archlinux.org/CVE-2021-22181 https://security.archlinux.org/CVE-2021-22213 https://security.archlinux.org/CVE-2021-22214 https://security.archlinux.org/CVE-2021-22216 https://security.archlinux.org/CVE-2021-22217 https://security.archlinux.org/CVE-2021-22218 https://security.archlinux.org/CVE-2021-22219 https://security.archlinux.org/CVE-2021-22220 https://security.archlinux.org/CVE-2021-22221 . Ubuntu Security Notice for PostgreSQL reveals critical vulnerabilities necessitating immediate updates to protect end-users.. Arch Linux, GitLab, High Severity Issues, Security Patch. . LinuxSecurity.com Team

Calendar%202 Jun 11, 2021 ArchLinux
198

Arch Linux Advisory ASA-202105-4 High Severity GitLab Issues

The package gitlab before version 13.10.4-1 is vulnerable to multiple issues including insufficient validation, access restriction bypass, denial of service and information disclosure. . Arch Linux Security Advisory ASA-202105-4 ======================================== Severity: High Date : 2021-05-19 CVE-ID : CVE-2021-22206 CVE-2021-22208 CVE-2021-22209 CVE-2021-22210 CVE-2021-22211 Package : gitlab Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1888 Summary ====== The package gitlab before version 13.10.4-1 is vulnerable to multiple issues including insufficient validation, access restriction bypass, denial of service and information disclosure. Resolution ========= Upgrade to 13.10.4-1. # pacman -Syu "gitlab> =13.10.4-1" The problems have been fixed upstream in version 13.10.4. Workaround ========= None. Description ========== - CVE-2021-22206 (information disclosure) An issue has been discovered in GitLab affecting all versions prior to 11.6. Pull mirror credentials were exposed and could allow other maintainers to view the credentials in plain-text. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7. - CVE-2021-22208 (access restriction bypass) An issue has been discovered in GitLab affecting versions prior to 13.5. Improper permission check could allow the change of timestamp for issue creation or update. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7. - CVE-2021-22209 (insufficient validation) An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7. - CVE-2021-22210 (denial of service) An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount ofresults. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7. - CVE-2021-22211 (access restriction bypass) An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7. Impact ===== A remote attacker could obtain sensitive pull mirror credentials, manipulate issue creation timestamps, execute GraphQL mutations, cause denial of service by generating large API query responses, or impersonate other users. References ========= https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#pull-mirror-credentials-were-exposed https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#non-owners-can-set-system_note_timestamp-when-creating--updating-issues https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#read-api-scoped-tokens-can-execute-mutations https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#denial-of-service-when-querying-repository-branches-api https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#deploytoken-will-impersonate-a-user-with-the-same-id-when-using-dependency-proxy https://security.archlinux.org/CVE-2021-22206 https://security.archlinux.org/CVE-2021-22208 https://security.archlinux.org/CVE-2021-22209 https://security.archlinux.org/CVE-2021-22210 https://security.archlinux.org/CVE-2021-22211 . Examine diverse problems influencing GitLab before release 13.10.4-1 in Arch Linux advisory ASA-202105-4.. GitLab Issues, Arch Linux Security, Access Control, Denial of Service. . LinuxSecurity.com Team

Calendar%202 May 20, 2021 ArchLinux
198

Arch Linux 202104-1 Critical Advisory: GitLab Code Execution Risk

The package gitlab before version 13.10.3-1 is vulnerable to multiple issues including arbitrary code execution and incorrect calculation. . Arch Linux Security Advisory ASA-202104-1 ======================================== Severity: Critical Date : 2021-04-29 CVE-ID : CVE-2021-22205 CVE-2021-28965 Package : gitlab Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1822 Summary ====== The package gitlab before version 13.10.3-1 is vulnerable to multiple issues including arbitrary code execution and incorrect calculation. Resolution ========= Upgrade to 13.10.3-1. # pacman -Syu "gitlab> =13.10.3-1" The problems have been fixed upstream in version 13.10.3. Workaround ========= None. Description ========== - CVE-2021-22205 (arbitrary code execution) An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that is passed to a file parser which resulted in a remote command execution. The issue is fixed in GitLab versions 13.10.3, 13.9.6 and 13.8.8. - CVE-2021-28965 (incorrect calculation) When parsing and serializing a crafted XML document, the REXML gem (including the one bundled with Ruby) can create a wrong XML document whose structure is different from the original one. The impact of this issue highly depends on context, but it may lead to a vulnerability in some programs that are using REXML. The issue is fixed in version 3.2.5 of the REXML gem. Impact ===== An attacker can crash or execute arbitrary code on the affected server by providing a maliciously crafted XML or imagefile. References ========= https://about.gitlab.com/releases/2021/04/14/security-release-gitlab-13-10-3-released/ https://about.gitlab.com/releases/2021/04/14/security-release-gitlab-13-10-3-released/#Remote-code-execution-when-uploading-specially-crafted-image-files https://gitlab.com/gitlab-org/gitlab/-/issues/327121 https://hackerone.com/reports/1154542 https://www.ruby-lang.org/en/news/2021/04/05/xml-round-trip-vulnerability-in-rexml-cve-2021-28965/ https://hackerone.com/reports/1104077 https://github.com/ruby/rexml/commit/a659c63e37414506dfb0d4655e031bb7a2e73fc8 https://github.com/ruby/rexml/commit/2fe62e29094d95921d7e19abbd2e26b23d78dc5b https://github.com/ruby/rexml/commit/6a250d2cd1194c2be72becbdd9c3e770aa16e752 https://github.com/ruby/rexml/commit/f7bab8937513b1403cea5aff874cbf32fd5e8551 https://github.com/ruby/rexml/commit/f9d88e4948b4a43294c25dc0edb16815bd9d8618 https://github.com/ruby/rexml/commit/9b311e59ae05749e082eb6bbefa1cb620d1a786e https://github.com/ruby/rexml/commit/3c137eb119550874b2b3e27d12b733ca67033377 https://security.archlinux.org/CVE-2021-22205 https://security.archlinux.org/CVE-2021-28965 . Severe flaws identified in GitLab prior to 13.10.3-1 pose risks; upgrading is advised for safeguarding.. GitLab Vulnerability, Arch Linux Advisory, Code Execution Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 29, 2021 Critical ArchLinux
198

Arch Linux: ASA-202103-13 Critical: GitLab Code Execution Risk

The package gitlab before version 13.9.4-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202103-13 ========================================= Severity: Critical Date : 2021-03-25 CVE-ID : CVE-2021-22192 Package : gitlab Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-1710 Summary ====== The package gitlab before version 13.9.4-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 13.9.4-1. # pacman -Syu "gitlab> =13.9.4-1" The problem has been fixed upstream in version 13.9.4. Workaround ========= None. Description ========== An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server. Impact ===== An authenticated malicious user is able to execute arbitrary code on the affected server. References ========= https://about.gitlab.com/releases/2021/03/17/security-release-gitlab-13-9-4-released/#remote-code-execution-via-unsafe-user-controlled-markdown-rendering-options https://hackerone.com/reports/1125425 https://gitlab.com/gitlab-org/gitlab/-/issues/324452 https://gitlab.com/gitlab-org/gitlab/-/commit/179329b5c3c118924fb242dc449d06b4ed6ccb66 https://security.archlinux.org/CVE-2021-22192 . The Arch Linux Security Notice ASA-202104-15 highlights a significant flaw in GitLab that could permit unauthorized code execution.. Arch Linux, GitLab Security, Arbitrary Code Execution, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 26, 2021 Critical ArchLinux
198

Arch Linux: 202102-11 Medium Severity GitLab Information Disclosure

The package gitlab before version 13.8.2-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-202102-11 ========================================= Severity: Medium Date : 2021-02-06 CVE-ID : CVE-2021-22172 Package : gitlab Type : information disclosure Remote : Yes Link : https://security.archlinux.org/AVG-1521 Summary ====== The package gitlab before version 13.8.2-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 13.8.2-1. # pacman -Syu "gitlab> =13.8.2-1" The problem has been fixed upstream in version 13.8.2. Workaround ========= None. Description ========== Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page. The issue is fixed in versions 13.8.2, 13.7.6 and 13.6.6. Impact ===== A guest user can view tag data that should be inaccessible on the releases page of a private project. References ========= https://gitlab.com/gitlab-org/gitlab-foss/-/commit/41b1c0469dba622a1c2c67c17f1f5e491573accf https://security.archlinux.org/CVE-2021-22172 . Arch Linux Security Bulletin ASA-202109-12, classified as Medium severity, outlines a GitLab vulnerability linked to information leakage and provides corresponding patches.. Arch Linux, GitLab, Information Disclosure. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Feb 12, 2021 Medium ArchLinux
198

Arch Linux: 202101-10 High Severity GitLab Authentication Bypass DoS

The package gitlab before version 13.7.2-1 is vulnerable to multiple issues including authentication bypass, denial of service and information disclosure. . Arch Linux Security Advisory ASA-202101-10 ========================================= Severity: High Date : 2021-01-12 CVE-ID : CVE-2020-26414 CVE-2021-22166 CVE-2021-22167 CVE-2021-22168 CVE-2021-22171 Package : gitlab Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1416 Summary ====== The package gitlab before version 13.7.2-1 is vulnerable to multiple issues including authentication bypass, denial of service and information disclosure. Resolution ========= Upgrade to 13.7.2-1. # pacman -Syu "gitlab> =13.7.2-1" The problems have been fixed upstream in version 13.7.2. Workaround ========= None. Description ========== - CVE-2020-26414 (denial of service) An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string. The issue is mitigated in GitLab version 13.7.2, 13.6.4, and 13.5.6. - CVE-2021-22166 (denial of service) An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method. The issue is mitigated in GitLab version 13.7.2. - CVE-2021-22167 (information disclosure) An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers within a specific project page allow attackers to have temporary read access to a public repository with project features restricted only to members. The issue is mitigated in GitLab version 13.7.2, 13.6.4, and 13.5.6. - CVE-2021-22168 (denial of service) A regular expression denial of service issue has been discovered in the NuGet API affecting all versions of GitLab starting from version 12.8. The issue is mitigated in GitLab version 13.7.2,13.6.4, and 13.5.6. - CVE-2021-22171 (authentication bypass) Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ would allow stealing a user's API access token. The issue is mitigated in GitLab version 13.7.2, 13.6.4, and 13.5.6. Note: A way to bypass the fix released in GitLab version 13.7.2, 13.6.4, and 13.5.6 has been found and was subsequently fixed in version 13.7.4, 13.6.5, and 13.5.7. Impact ===== A malicious authenticated user might crash the application through a malformed HTTP request or project name, bypass authentication or disclose private information. References ========= https://about.gitlab.com/releases/2021/01/07/security-release-gitlab-13-7-2-released/ https://about.gitlab.com/releases/2021/01/07/security-release-gitlab-13-7-2-released/#regular-expression-denial-of-service-in-package-uploads https://about.gitlab.com/releases/2021/01/07/security-release-gitlab-13-7-2-released/#prometheus-denial-of-service-via-http-request-with-custom-method https://about.gitlab.com/releases/2021/01/07/security-release-gitlab-13-7-2-released/#unauthorized-user-is-able-to-access-private-repository-information-under-specific-conditions https://about.gitlab.com/releases/2021/01/07/security-release-gitlab-13-7-2-released/#regular-expression-denial-of-service-in-nuget-api https://about.gitlab.com/releases/2021/01/07/security-release-gitlab-13-7-2-released/#ability-to-steal-a-users-api-access-token-through-gitlab-pages https://gitlab.com/gitlab-org/gitlab-foss/-/commit/fa70ce1068babe592d348497c772f1b5160cbb6e https://gitlab.com/gitlab-org/gitlab-foss/-/commit/e861919633e0aac16509c0415f71eda69902bff9 https://security.archlinux.org/CVE-2020-26414 https://security.archlinux.org/CVE-2021-22166 https://security.archlinux.org/CVE-2021-22167 https://security.archlinux.org/CVE-2021-22168 https://security.archlinux.org/CVE-2021-22171 . Update your GitLab to version 13.7.2-1 to address critical security vulnerabilities, such as authentication bypassrisks.. GitLab Issues, Arch Linux Advisory, Security Risks. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2021 ArchLinux
198

ArchLinux: 201810-16 Critical: GitLab Code Execution Risks

The package gitlab before version 11.4.3-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery, cross-site scripting and information disclosure. . Arch Linux Security Advisory ASA-201810-16 ========================================= Severity: Critical Date : 2018-10-31 CVE-ID : CVE-2018-18640 CVE-2018-18641 CVE-2018-18643 CVE-2018-18645 CVE-2018-18646 CVE-2018-18648 CVE-2018-18649 Package : gitlab Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-794 Summary ====== The package gitlab before version 11.4.3-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery, cross-site scripting and information disclosure. Resolution ========= Upgrade to 11.4.3-1. # pacman -Syu "gitlab> =11.4.3-1" The problems have been fixed upstream in version 11.4.3. Workaround ========= None. Description ========== - CVE-2018-18640 (information disclosure) A security issue has been found in gitlab versions prior to 11.4.3, where private project pages had inadequate cache control, which resulted in unauthorized users being able to view them in the browser. - CVE-2018-18641 (information disclosure) A security issue has been found in gitlab versions prior to 11.4.3, where personal access tokens were being stored unencrypted as plain text in the database which could result in attackers potentially reading them via SQL injection or other database leaks. - CVE-2018-18643 (cross-site scripting) A security issue has been found in gitlab versions prior to 11.4.3, where the fragment identifier (hash) of several pages contained a lack of input validation and output encoding issue which resulted in a persistent XSS. - CVE-2018-18645 (information disclosure) A security issue has been found in gitlab versions prior to 11.4.3, where when replying to an issue through email, with the GitLab email footer included, a user's unsubscribe link would be included in the issue. This information is consideredsensitive. - CVE-2018-18646 (cross-site request forgery) A security issue has been found in gitlab versions prior to 11.4.3, where the Hipchat integration was vulnerable to a SSRF issue which allowed an attacker to make requests to any local network resource accessible from the GitLab server. - CVE-2018-18648 (information disclosure) A security issue has been found in gitlab versions prior to 11.4.3, where a JSON endpoint was disclosing Gem version information which could result in an attacker discovering vulnerable Gems available on a specific GitLab instance. - CVE-2018-18649 (arbitrary code execution) A security issue has been found in gitlab versions prior to 11.4.3, where the wiki API contained an input validation issue which resulted in remote code execution. Impact ===== A remote attacker is able to execute arbitrary code, disclose information, perform cross-site request forgery or cross-site scripting. References ========= https://gitlab.com/gitlab-org/gitlab-foss/-/commit/5e125b0f84ad768d7ff19905d03820f561c21f98 https://gitlab.com/gitlab-org/gitlab-foss/-/commit/daed01a5ca348e7d267b50e325bf58185617a0ad https://gitlab.com/gitlab-org/gitlab-foss/-/commit/5342df04045e1c8a98fdb9fe8203a816bf240ac8 https://gitlab.com/gitlab-org/gitlab-foss/-/commit/82c12bd8bf9e0ea9e8df3bbcad91c27fccc709e8 https://gitlab.com/gitlab-org/gitlab-foss/-/commit/f17e36feab266a62b316bfe88d7d558c2debaf9b https://gitlab.com/gitlab-org/gitlab-foss/-/commit/b9b68fe7d30778338625fb606457eb1886a17f08 https://gitlab.com/gitlab-org/gitlab-foss/-/commit/e05636e2794d975876958c3781b66de2991d89d2 https://security.archlinux.org/CVE-2018-18640 https://security.archlinux.org/CVE-2018-18641 https://security.archlinux.org/CVE-2018-18643 https://security.archlinux.org/CVE-2018-18645 https://security.archlinux.org/CVE-2018-18646 https://security.archlinux.org/CVE-2018-18648 https://security.archlinux.org/CVE-2018-18649 . Essential Arch Linux Security Bulletin ASA-201810-17 highlights various vulnerabilities in GitLab. Immediate update isrequired.. GitLab Security Bug, ArchLinux Advisory, Package Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 31, 2018 Critical ArchLinux
198

Arch Linux: 201807-1 Medium: GitLab XSS and Validation Issues

The package gitlab before version 11.0.1-1 is vulnerable to multiple issues including cross-site scripting and insufficient validation. . Arch Linux Security Advisory ASA-201807-1 ======================================== Severity: Medium Date : 2018-07-04 CVE-ID : CVE-2018-3740 CVE-2018-12606 CVE-2018-12607 Package : gitlab Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-726 Summary ====== The package gitlab before version 11.0.1-1 is vulnerable to multiple issues including cross-site scripting and insufficient validation. Resolution ========= Upgrade to 11.0.1-1. # pacman -Syu "gitlab> =11.0.1-1" The problems have been fixed upstream in version 11.0.1. Workaround ========= None. Description ========== - CVE-2018-3740 (insufficient validation) A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element. - CVE-2018-12606 (cross-site scripting) The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature. - CVE-2018-12607 (cross-site scripting) The charts feature contained a persistent XSS issue due to a lack of output encoding. Impact ===== An attacker is able to use a GitLab server to execute malicious Javascript code on its users via a crafted HTML chart or specific markdown features. References ========= https://security.archlinux.org/CVE-2018-3740 https://security.archlinux.org/CVE-2018-12606 https://security.archlinux.org/CVE-2018-12607 . Arch Linux Security Advisory ASA-201807-1 ======================================== Severity: Medium . package, gitlab, version, vulnerable, cross-site. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jul 04, 2018 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200