From nobody Fri Sep 1 05:33:44 2023 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RcRXS2sfWz4s5Bl; Fri, 1 Sep 2023 05:33:44 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RcRXS2Kqkz4YDQ; Fri, 1 Sep 2023 05:33:44 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1693546424; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=IQRGrT5wVgHhh1E6w9MXoyyfBY8Rd5A3jCkIU0M48Gs=; b=KR5R9ed3A3WjdhyHW6aU8Djpd0trTMYgMP1sWYWdekLso/a+Bx4khomHKKi+JYFICA5sD5 swjOSjPIfRhWdhSWCy6JELJaI+bAQzaBFYYj/uN+jq8L1MQ12wNlx2m3xBc2nO+v0KZDJR ddu0qSFQpD4k55jhhD3aXKuZaAV5DkBUpe2XQYiMPkVn1Q+jzHc4ldyo7aN6Gc8vIM3uar ZMv/uVDtM/Z8ZDD9JyHG5JwbIrDNvCiIk2qcVyc26w7x5sdCZbgKCMNTdLce30M14+4aio KxM+20uVbF0eImMugyZJhluHRJE4BrUM1/u4GNJqkY+/2Lix6pY2POeLh65TXQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1693546424; a=rsa-sha256; cv=none; b=MFIGXEuE44u+ektykya4blfzCVjNKsArJky7SzLHYiQ/vp3bSGhGxfb/JEF3VQoWbqjcuz x7Nt2iQxBRtjzcOFPNHm+FtVylt1BMKm42rDVAKqsaIQoyLNteKjmGiKALOotICk3UmyUz huKSfIkNmcaJiGKem3W88JjMffL6TWUbyw5ewZAmuXA1lSm6GpX0VBUAtFGJ+F802yrEqU 7Jpe7Fa3vk5KPpj2gu00LgSQngaeZoZVEKTiHTn97OjOFM2w6JT4IkjLh2Um0yvolvJ//U ZppDBniCIqRJRvHvpVVlVnYZDQmDivRbvNJfn3rfKYilJYD6ILRU9KvtrRxMbA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1693546424; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=IQRGrT5wVgHhh1E6w9MXoyyfBY8Rd5A3jCkIU0M48Gs=; b=TIhODRGJdUcFAysNu0pL9aum8UR+Un/zlmPfMYrNwvnNPCtls0rfQ4rq0eo0jlMs5ul6KO tvi9gUiHBIpBR/qxGJ/Wi6HuPhSm5jPkZRbQL4+7kS/9IxNF2FuMQdJqhJcWkt0rp3/43n o1JMbCWUCUL8XE7R7Q4G7YhBZ0u/w8WUya26WnN4/7GjZ8PcunGRmsVV+0y17H+p5XTIgh pzAxDc3CADWUprwzrF24noOc+ljyTdfP9nc3zqhDuBgRH+/Pw8FCHi+wo2dtrSxEDXrc5m X/j79TsFRRZaGSrZxRfR5Hp3mf6hWVW6vKjDGJLTrd6uddYj5fuNHdrKMA1r0Q== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RcRXS13mWzp8g; Fri, 1 Sep 2023 05:33:44 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 3815Xi2E042173; Fri, 1 Sep 2023 05:33:44 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 3815Xi36042170; Fri, 1 Sep 2023 05:33:44 GMT (envelope-from git) Date: Fri, 1 Sep 2023 05:33:44 GMT Message-Id: <202309010533.3815Xi36042170@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Matthias Fechner Subject: git: e903024f0d93 - main - security/vuxml: document gitlab vulnerabilities List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: mfechner X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: e903024f0d9399f639a45c7b3b683620fcaf518b Auto-Submitted: auto-generated The branch main has been updated by mfechner: URL: https://cgit.FreeBSD.org/ports/commit/?id=e903024f0d9399f639a45c7b3b683620fcaf518b commit e903024f0d9399f639a45c7b3b683620fcaf518b Author: Matthias Fechner AuthorDate: 2023-09-01 05:33:18 +0000 Commit: Matthias Fechner CommitDate: 2023-09-01 05:33:18 +0000 security/vuxml: document gitlab vulnerabilities --- security/vuxml/vuln/2023.xml | 50 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml index 902e6a2dbd4b..47b4a78c53f4 100644 --- a/security/vuxml/vuln/2023.xml +++ b/security/vuxml/vuln/2023.xml @@ -1,3 +1,53 @@ + + Gitlab -- Vulnerabilities + + + gitlab-ce + 16.3.016.3.1 + 16.2.016.2.5 + 4.1.016.1.5 + + + + +

Gitlab reports:

+
+

Privilege escalation of "external user" to internal access through group service account

+

Maintainer can leak sentry token by changing the configured URL (fix bypass)

+

Google Cloud Logging private key showed in plain text in GitLab UI leaking to other group owners

+

Information disclosure via project import endpoint

+

Developer can leak DAST scanners "Site Profile" request headers and auth password

+

Project forking outside current group

+

User is capable of creating Model experiment and updating existing run's status in public project

+

ReDoS in bulk import API

+

Pagination for Branches and Tags can be skipped leading to DoS

+

Internal Open Redirection Due to Improper handling of "../" characters

+

Subgroup Member With Reporter Role Can Edit Group Labels

+

Banned user can delete package registries

+
+ +
+ + CVE-2023-3915 + CVE-2023-4378 + CVE-2023-3950 + CVE-2023-4630 + CVE-2022-4343 + CVE-2023-4638 + CVE-2023-4018 + CVE-2023-3205 + CVE-2023-4647 + CVE-2023-1279 + CVE-2023-0120 + CVE-2023-1555 + https://about.gitlab.com/releases/2023/08/31/security-release-gitlab-16-3-1-released/ + + + 2023-08-31 + 2023-09-01 + +
+ Borg (Backup) -- flaw in cryptographic authentication scheme in Borg allowed an attacker to fake archives and indirectly cause backup data loss.