Debian Security Advisory
DSA-4145-1 gitlab -- security update
- Date Reported:
- 18 Mar 2018
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-0915, CVE-2017-0916, CVE-2017-0917, CVE-2017-0918, CVE-2017-0925, CVE-2017-0926, CVE-2018-3710.
- More information:
Several vulnerabilities have been discovered in Gitlab, a software platform to collaborate on code:
Arbitrary code execution in project import.
Command injection via Webhooks.
Cross-site scripting in CI job output.
Insufficient restriction of CI runner for project cache access.
Information disclosure in Services API.
Restrictions for disabled OAuth providers could be bypassed.
For the stable distribution (stretch), these problems have been fixed in version 8.13.11+dfsg1-8+deb9u1.
We recommend that you upgrade your gitlab packages.
For the detailed security status of gitlab please refer to its security tracker page at: https://security-tracker.debian.org/tracker/gitlab
- CVE-2017-0915 / CVE-2018-3710