--- security/vuxml/vuln.xml (revision 425795) +++ security/vuxml/vuln.xml (working copy) @@ -58,6 +58,40 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + gitlab -- Directory traversal via "import/export" feature + + + rubygem-gitlab + 8.10.08.10.12 + 8.11.08.11.9 + 8.12.08.12.7 + 8.13.08.13.2 + + + + +

GitLab reports:

+
+

The import/export feature did not properly check for symbolic links + in user-provided archives and therefore it was possible for an + authenticated user to retrieve the contents of any file + accessible to the GitLab service account. This included + sensitive files such as those that contain secret tokens used + by the GitLab service to authenticate users.

+
+ +
+ + https://about.gitlab.com/2016/11/02/cve-2016-9086-patches/ + CVE-2016-9086 + + + 2016-11-02 + 2016-11-09 + +
+ chromium -- out-of-bounds memory access