~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2016-9469

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2016-9469
2
 
PublicDate: 2017-03-27
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9469
5
 
 https://about.gitlab.com/2016/12/05/cve-2016-9469/
6
 
 https://gitlab.com/gitlab-org/gitlab-ce/issues/25064
7
 
Description:
8
 
 Multiple versions of GitLab expose a dangerous method to any authenticated
9
 
 user that could lead to the deletion of all Issue and MergeRequest objects
10
 
 on a GitLab instance. For GitLab instances with publicly available projects
11
 
 this vulnerability could be exploited by an unauthenticated user. A fix was
12
 
 included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on
13
 
 December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are
14
 
 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee,
15
 
 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0,
16
 
 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.
17
 
Ubuntu-Description:
18
 
Notes:
19
 
 ratliff> GitLab says that affected versions include 8.14.0 through 8.14.2
20
 
 ratliff> and 8.13.0 through 8.13.7
21
 
Bugs:
22
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=847157
23
 
Priority: medium
24
 
Discovered-by: Jobert Abma
25
 
Assigned-to:
26
 
 
27
 
Patches_gitlab:
28
 
upstream_gitlab: needs-triage
29
 
precise_gitlab: DNE
30
 
precise/esm_gitlab: DNE
31
 
trusty_gitlab: DNE
32
 
vivid/stable-phone-overlay_gitlab: DNE
33
 
vivid/ubuntu-core_gitlab: DNE
34
 
xenial_gitlab: not-affected (8.5.8+dfsg-5)
35
 
yakkety_gitlab: not-affected (8.11.3+dfsg1-1)
36
 
zesty_gitlab: ignored (reached end-of-life)
37
 
artful_gitlab: needed
38
 
bionic_gitlab: DNE
39
 
devel_gitlab: DNE