
The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the a1a1b0c2-3791-11f0-8600-2cf05da270f3 advisory. Gitlab reports: Unprotected large blob endpoint in GitLab allows Denial of Service Improper XPath validation allows modified SAML response to bypass 2FA requirement A Discord webhook integration may cause DoS Unbounded Kubernetes cluster tokens may lead to DoS Unvalidated notes position may lead to Denial of Service Hidden/masked variables may get exposed in the UI Two-factor authentication requirement bypass View full email addresses that should be partially obscured Branch name confusion in confidential MRs Unauthorized access to job data via a GraphQL query Tenable has extracted the preceding description block directly from the FreeBSD security advisory. Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version…Read More
References
Back to Main