Jump to content
net3design

Security Vulnerability in Gitlab (CVE-2013-7316)

Recommended Posts

9dcc4f29a04659227a2c99e482c22589.png

Security vulnerability in GitLab (CVE-2013-7316)

We have learned about a XSS vulnerability in GitLab. This issue was fixed in GitLab 6.5.

Cross-site scripting (XSS) vulnerability in GitLab

A cross-site scripting (XSS) vulnerability in GitLab allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file. This vulnerability has been assigned the CVE identifier CVE-2013-7316.

Versions affected: 6.4 and earlier

Fixed versions: Community Edition 6.5.0, Enterprise Edition 6.5.0

Impact

In affected versions, when adding a README with voluntary extension the file would be rendered with markup. This would allow an attacker to add a script that would be executed on the client side.

This vulnerability was fixed in GitLab 6.5. All users running GitLab 6.4 and earlier versions should upgrade immediately.

Releases

Gitlab 6.5 Community Edition is available from https://gitlab.com/gitlab-org/gitlab-ce and https://github.com/gitlabhq/gitlabhq . GitLab 6.5 Enterprise Edition is available for subscribers from GitLab Cloud. Please follow the upgrade guides from your current version to version 6.5.

Credits

Thanks to ChenQin, Network and Information Security Lab @ Tsinghua University for reporting the vulnerability.

Source : GitLab Blog

  • Upvote 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...