Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2018.0065 GitLab Critical Security Release: 10.5.6, 10.4.6, and 10.3.9 29 March 2018 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: GitLab Operating System: Linux variants Windows Virtualisation Impact/Access: Execute Arbitrary Code/Commands -- Remote/Unauthenticated Access Confidential Data -- Remote/Unauthenticated Unauthorised Access -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2018-8801 Member content until: Saturday, April 28 2018 OVERVIEW Multiple vulnerabilities have been identified in GitLab Community dition (CE) and Enterprise Edition (EE) prior to versions 10.5.6, 10.4.6, and 10.3.9. [1] IMPACT The vendor has provided the following details regarding the vulnerabilities: "There were multiple server-side request forgery issues in the Services feature. An attacker could make requests to servers within the same network of the GitLab instance. This could lead to information disclosure, authentication bypass, or potentially code execution. This issue has been assigned CVE-2018-8801. Thanks to @jobert from HackerOne for reporting this. Versions Affected Affects GitLab CE/EE 8.3 and up"[1] MITIGATION The vendor strongly recommends users upgrade to the latest versions to fix these issues. [1] REFERENCES [1] GitLab Critical Security Release: 10.5.6, 10.4.6, and 10.3.9 https://about.gitlab.com/2018/03/20/critical-security-release-gitlab-10-dot-5-dot-6-released/ AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBWryD9Ix+lLeg9Ub1AQj9SRAAp3cFG771gaaVdCipXaz8s+LgyNQCfule vbDLQTTztyVxXpRmk59mf4S6g2TK9JYIBAVmXVTJb5xNl8iTaYEimNCwjsFTudU6 e5msRKBj2y5lIVacSqADGwmTyqNG3zfza47jVgjfjVa/EpPMGUUhinN46mkQWUEV lGjkVcP8rJdCMAN3KXEvLDOkvzNkmWpStzbX2E06I23pB4EooTMWIjCSyjF1MWn4 mS+YfmCw9y8Ywe4VpCSDASxoeGeSgQwogC9jh/IK8GN+4rmmeBD+c2oYrzALcgYu apnPf+x5dkpbhxiFIv0Yu11VtFoZ34KYXo18v/f/G17l2m5zaPPjn8CQcJGUjRyd BZDoCALEczEuTj6KufYaYj6CvseJRhJNPyJIWgd4tCDE6MKSoe5vQL6Q4gM7EWex HC5FKuoM77vomxpoWM4iNOlMLMPx8Hgj90VunVk1VctsWWaMANEUlaTvXBnCHz9l VVIkckUKdobhb86yl9yMzrVq2HMnlXuDeODA5HpRQDjiOLM07KCcFThCOMS/+Bje 0uboVLvLXoUdL3tXoZI1CsnfFZ+ISJdz1gfS5IscpOItMwRKiHPnCb1pKJaVycIs QDkMrpjx54QoE7QNvj5hAxWxWJuJU9QXH/C6PV/ydnH+RSwAA9LRA2zYOYIMNuOw Bp2H2BfiBGs= =uewB -----END PGP SIGNATURE-----