Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.
From VID-B2F4AB91-0E6B-11E9-8700-001B217B3468:
Gitlab reports:
Source code disclosure merge request diff
Todos improper access control
URL rel attribute not set
Persistent XSS Autocompletion
SSRF repository mirroring
CI job token LFS error message disclosure
Secret CI variable exposure
Guest user CI job disclosure
Persistent XSS label reference
Persistent XSS wiki in IE browser
SSRF in project imports with LFS
Improper access control CI/CD settings
Missing authorization control merge requests
Improper access control branches and tags
Missing authentication for Prometheus alert endpoint
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center