vulnerability

FreeBSD: VID-3507bfb3-85d5-11ec-8c9c-001b217b3468 (CVE-2022-0427): Gitlab -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Feb 4, 2022
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

Gitlab reports: Arbitrary POST requests via special HTML attributes in Jupyter Notebooks DNS Rebinding vulnerability in Irker IRC Gateway integration Missing certificate validation for external CI services Blind SSRF Through Project Import Open redirect vulnerability in Jira Integration Issue link was disclosing the linked issue Service desk email accessible by project non-members Authenticated users can search other users by their private email "External status checks" can be accepted by users below developer access if the user is either author or assignee of the target merge request Deleting packages in bulk from package registries may cause table locks Autocomplete enabled on specific pages Possible SSRF due to not blocking shared address space System notes reveals private project path when Issue is moved to a public project Timeout for pages using Markdown Certain branch names could not be protected

Solution

freebsd-upgrade-package-gitlab-ce
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.