From bd7c65e6eb0e8d84ffb4b1dbfd8be41cfe9b4530 Mon Sep 17 00:00:00 2001 From: CVE Team Date: Mon, 9 Sep 2019 20:00:49 +0000 Subject: [PATCH] "-Synchronized-Data." --- 2019/16xxx/CVE-2019-16190.json | 62 ++++++++++++++++++++++++++++++++++ 2019/6xxx/CVE-2019-6781.json | 12 +++---- 2019/6xxx/CVE-2019-6782.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6783.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6784.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6785.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6786.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6788.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6789.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6790.json | 12 +++---- 2019/6xxx/CVE-2019-6792.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6793.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6794.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6795.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6796.json | 26 +++++++------- 2019/6xxx/CVE-2019-6960.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6995.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6996.json | 53 +++++++++++++++++++++++++++-- 2019/6xxx/CVE-2019-6997.json | 53 +++++++++++++++++++++++++++-- 2019/7xxx/CVE-2019-7155.json | 7 +--- 2019/7xxx/CVE-2019-7353.json | 15 +++----- 21 files changed, 858 insertions(+), 71 deletions(-) create mode 100644 2019/16xxx/CVE-2019-16190.json diff --git a/2019/16xxx/CVE-2019-16190.json b/2019/16xxx/CVE-2019-16190.json new file mode 100644 index 00000000000..441cec91192 --- /dev/null +++ b/2019/16xxx/CVE-2019-16190.json @@ -0,0 +1,62 @@ +{ + "CVE_data_meta": { + "ASSIGNER": "cve@mitre.org", + "ID": "CVE-2019-16190", + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } + }, + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", + "description": { + "description_data": [ + { + "lang": "eng", + "value": "SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "url": "https://cyberloginit.com/2019/09/10/dlink-shareport-web-access-authentication-bypass.html", + "refsource": "MISC", + "name": "https://cyberloginit.com/2019/09/10/dlink-shareport-web-access-authentication-bypass.html" + } + ] + } +} \ No newline at end of file diff --git a/2019/6xxx/CVE-2019-6781.json b/2019/6xxx/CVE-2019-6781.json index 93bdbd9f966..57e9d3b0d89 100644 --- a/2019/6xxx/CVE-2019-6781.json +++ b/2019/6xxx/CVE-2019-6781.json @@ -53,14 +53,14 @@ "references": { "reference_data": [ { - "url": "https://about.gitlab.com/blog/categories/releases/", - "refsource": "MISC", - "name": "https://about.gitlab.com/blog/categories/releases/" + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" }, { - "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", - "refsource": "MISC", - "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/22076", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/22076" } ] } diff --git a/2019/6xxx/CVE-2019-6782.json b/2019/6xxx/CVE-2019-6782.json index c00e577cae8..68a5b6559a7 100644 --- a/2019/6xxx/CVE-2019-6782.json +++ b/2019/6xxx/CVE-2019-6782.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6782", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/52677", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/52677" } ] } diff --git a/2019/6xxx/CVE-2019-6783.json b/2019/6xxx/CVE-2019-6783.json index b9ae0b88919..d22fd5a2785 100644 --- a/2019/6xxx/CVE-2019-6783.json +++ b/2019/6xxx/CVE-2019-6783.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6783", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/55827", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/55827" } ] } diff --git a/2019/6xxx/CVE-2019-6784.json b/2019/6xxx/CVE-2019-6784.json index b6552784f73..c20020dbc75 100644 --- a/2019/6xxx/CVE-2019-6784.json +++ b/2019/6xxx/CVE-2019-6784.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6784", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/54416", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/54416" } ] } diff --git a/2019/6xxx/CVE-2019-6785.json b/2019/6xxx/CVE-2019-6785.json index ab55fe04dbe..ea9efc16678 100644 --- a/2019/6xxx/CVE-2019-6785.json +++ b/2019/6xxx/CVE-2019-6785.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6785", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/52212", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/52212" } ] } diff --git a/2019/6xxx/CVE-2019-6786.json b/2019/6xxx/CVE-2019-6786.json index b5548acce7f..254d8e928df 100644 --- a/2019/6xxx/CVE-2019-6786.json +++ b/2019/6xxx/CVE-2019-6786.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6786", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-workhorse/issues/197", + "url": "https://gitlab.com/gitlab-org/gitlab-workhorse/issues/197" } ] } diff --git a/2019/6xxx/CVE-2019-6788.json b/2019/6xxx/CVE-2019-6788.json index 9fe9c0dd61b..57e40e83e4b 100644 --- a/2019/6xxx/CVE-2019-6788.json +++ b/2019/6xxx/CVE-2019-6788.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6788", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/56663", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/56663" } ] } diff --git a/2019/6xxx/CVE-2019-6789.json b/2019/6xxx/CVE-2019-6789.json index 0507518190e..3935ea844bd 100644 --- a/2019/6xxx/CVE-2019-6789.json +++ b/2019/6xxx/CVE-2019-6789.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6789", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/44558", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/44558" } ] } diff --git a/2019/6xxx/CVE-2019-6790.json b/2019/6xxx/CVE-2019-6790.json index 0250b767b50..487b164195c 100644 --- a/2019/6xxx/CVE-2019-6790.json +++ b/2019/6xxx/CVE-2019-6790.json @@ -53,14 +53,14 @@ "references": { "reference_data": [ { - "url": "https://about.gitlab.com/blog/categories/releases/", - "refsource": "MISC", - "name": "https://about.gitlab.com/blog/categories/releases/" + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" }, { - "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", - "refsource": "MISC", - "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/51328", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/51328" } ] } diff --git a/2019/6xxx/CVE-2019-6792.json b/2019/6xxx/CVE-2019-6792.json index 9913c9de594..c00479685f6 100644 --- a/2019/6xxx/CVE-2019-6792.json +++ b/2019/6xxx/CVE-2019-6792.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6792", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/54867", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/54867" } ] } diff --git a/2019/6xxx/CVE-2019-6793.json b/2019/6xxx/CVE-2019-6793.json index 880e166475e..bb0de21b8f2 100644 --- a/2019/6xxx/CVE-2019-6793.json +++ b/2019/6xxx/CVE-2019-6793.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6793", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/50748", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/50748" } ] } diff --git a/2019/6xxx/CVE-2019-6794.json b/2019/6xxx/CVE-2019-6794.json index bbb536976e5..000cb91b956 100644 --- a/2019/6xxx/CVE-2019-6794.json +++ b/2019/6xxx/CVE-2019-6794.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6794", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/54353", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/54353" } ] } diff --git a/2019/6xxx/CVE-2019-6795.json b/2019/6xxx/CVE-2019-6795.json index d6264f56ffa..12ceba8e7d6 100644 --- a/2019/6xxx/CVE-2019-6795.json +++ b/2019/6xxx/CVE-2019-6795.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6795", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be used for social engineering." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/29365", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/29365" } ] } diff --git a/2019/6xxx/CVE-2019-6796.json b/2019/6xxx/CVE-2019-6796.json index 5cc233b3f51..e50fe5b9dec 100644 --- a/2019/6xxx/CVE-2019-6796.json +++ b/2019/6xxx/CVE-2019-6796.json @@ -34,7 +34,7 @@ "description_data": [ { "lang": "eng", - "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2)." + "value": "An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack of input validation and output encoding that results in a persistent XSS." } ] }, @@ -53,24 +53,24 @@ "references": { "reference_data": [ { - "url": "https://about.gitlab.com/blog/categories/releases/", - "refsource": "MISC", - "name": "https://about.gitlab.com/blog/categories/releases/" + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" }, { - "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", - "refsource": "MISC", - "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/", + "url": "https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/" }, { - "url": "https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/", - "refsource": "MISC", - "name": "https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/" - }, - { - "refsource": "MISC", + "refsource": "CONFIRM", "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/57112", "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/57112" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/55320", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/55320" } ] } diff --git a/2019/6xxx/CVE-2019-6960.json b/2019/6xxx/CVE-2019-6960.json index 133c7720ffc..9d8e70406a4 100644 --- a/2019/6xxx/CVE-2019-6960.json +++ b/2019/6xxx/CVE-2019-6960.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6960", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/54357", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/54357" } ] } diff --git a/2019/6xxx/CVE-2019-6995.json b/2019/6xxx/CVE-2019-6995.json index 59f964d99bf..0d44445da46 100644 --- a/2019/6xxx/CVE-2019-6995.json +++ b/2019/6xxx/CVE-2019-6995.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6995", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/55537", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/55537" } ] } diff --git a/2019/6xxx/CVE-2019-6996.json b/2019/6xxx/CVE-2019-6996.json index 580d6535ac9..4c9917d8d74 100644 --- a/2019/6xxx/CVE-2019-6996.json +++ b/2019/6xxx/CVE-2019-6996.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6996", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ee/issues/8187", + "url": "https://gitlab.com/gitlab-org/gitlab-ee/issues/8187" } ] } diff --git a/2019/6xxx/CVE-2019-6997.json b/2019/6xxx/CVE-2019-6997.json index d8897cdb9f6..b1b9c51e98d 100644 --- a/2019/6xxx/CVE-2019-6997.json +++ b/2019/6xxx/CVE-2019-6997.json @@ -2,7 +2,30 @@ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-6997", - "STATE": "RESERVED" + "STATE": "PUBLIC" + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "n/a", + "version": { + "version_data": [ + { + "version_value": "n/a" + } + ] + } + } + ] + }, + "vendor_name": "n/a" + } + ] + } }, "data_format": "MITRE", "data_type": "CVE", @@ -11,7 +34,33 @@ "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "n/a" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", + "url": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/" + }, + { + "refsource": "CONFIRM", + "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/53858", + "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/53858" } ] } diff --git a/2019/7xxx/CVE-2019-7155.json b/2019/7xxx/CVE-2019-7155.json index f7deceded72..f42fb6556b0 100644 --- a/2019/7xxx/CVE-2019-7155.json +++ b/2019/7xxx/CVE-2019-7155.json @@ -34,7 +34,7 @@ "description_data": [ { "lang": "eng", - "value": "An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control." + "value": "An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group." } ] }, @@ -52,11 +52,6 @@ }, "references": { "reference_data": [ - { - "url": "https://about.gitlab.com/blog/categories/releases/", - "refsource": "MISC", - "name": "https://about.gitlab.com/blog/categories/releases/" - }, { "refsource": "CONFIRM", "name": "https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/", diff --git a/2019/7xxx/CVE-2019-7353.json b/2019/7xxx/CVE-2019-7353.json index 714511b1cb5..9ad72432898 100644 --- a/2019/7xxx/CVE-2019-7353.json +++ b/2019/7xxx/CVE-2019-7353.json @@ -52,20 +52,15 @@ }, "references": { "reference_data": [ - { - "url": "https://about.gitlab.com/blog/categories/releases/", - "refsource": "MISC", - "name": "https://about.gitlab.com/blog/categories/releases/" - }, - { - "url": "https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/", - "refsource": "MISC", - "name": "https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/" - }, { "refsource": "CONFIRM", "name": "https://gitlab.com/gitlab-org/gitlab-ce/issues/56568", "url": "https://gitlab.com/gitlab-org/gitlab-ce/issues/56568" + }, + { + "refsource": "CONFIRM", + "name": "https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/", + "url": "https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/" } ] }