8.2

CVE-2016-9469

Exploit
Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab Version 8.13.0
Gitlab ≫ GitLab Version 8.13.0 SwEdition enterprise
Gitlab ≫ GitLab Version 8.13.1
Gitlab ≫ GitLab Version 8.13.1 SwEdition enterprise
Gitlab ≫ GitLab Version 8.13.2
Gitlab ≫ GitLab Version 8.13.2 SwEdition enterprise
Gitlab ≫ GitLab Version 8.13.3
Gitlab ≫ GitLab Version 8.13.3 SwEdition enterprise
Gitlab ≫ GitLab Version 8.13.4
Gitlab ≫ GitLab Version 8.13.4 SwEdition enterprise
Gitlab ≫ GitLab Version 8.13.5
Gitlab ≫ GitLab Version 8.13.5 SwEdition enterprise
Gitlab ≫ GitLab Version 8.13.6
Gitlab ≫ GitLab Version 8.13.6 SwEdition enterprise
Gitlab ≫ GitLab Version 8.13.7
Gitlab ≫ GitLab Version 8.13.7 SwEdition enterprise
Gitlab ≫ GitLab Version 8.14.0
Gitlab ≫ GitLab Version 8.14.0 SwEdition enterprise
Gitlab ≫ GitLab Version 8.14.1
Gitlab ≫ GitLab Version 8.14.1 SwEdition enterprise
Gitlab ≫ GitLab Version 8.14.2
Gitlab ≫ GitLab Version 8.14.2 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.4% 0.819
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 3.9 4.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-749 Exposed Dangerous Method or Function

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

https://about.gitlab.com/2016/12/05/cve-2016-9469/
Patch
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab-ce/commit/29ceb98b5162677601702704e89d845580372078
Patch
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab-ce/commit/55196497301eea429913f9c4b1b37c42c2e358ce
Patch
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab-ce/commit/f325e4e734e5e486f3b02db176eb629124052b43
Patch
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab-ce/issues/25064
Vendor Advisory
Exploit
https://hackerone.com/reports/186194
Third Party Advisory
Exploit
Technical Description