Gitlab Security Update for Debian 9
Posted on: 05/22/2018 07:22 AM

Updated gitlab packages has been released for Debian GNU/Linux 9

Gitlab Security Update for Debian 9

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4206-1 Moritz Muehlenhoff
May 21, 2018
- -------------------------------------------------------------------------

Package : gitlab
CVE ID : CVE-2017-0920 CVE-2018-8971

Several vulnerabilities have been discovered in Gitlab, a software
platform to collaborate on code:


It was discovered that missing validation of merge requests allowed
users to see names to private projects, resulting in information


It was discovered that the Auth0 integration was implemented

For the stable distribution (stretch), these problems have been fixed in
version 8.13.11+dfsg1-8+deb9u2. The fix for CVE-2018-8971 also requires
ruby-omniauth-auth0 to be upgraded to version 2.0.0-0+deb9u1.

We recommend that you upgrade your gitlab packages.

For the detailed security status of gitlab please refer to
its security tracker page at:

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at:

Printed from Linux Compatible (