CVE-2016-9086

MEDIUM

GitLab 8.9.0-8.13.2 - Authenticated Sensitive Information Exposure via Project Import/Export

Title source: llm
STIX 2.1

Description

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.

References (2)

Core 2
Core References
Mitigation, Patch, Vendor Advisory x_refsource_confirm
https://about.gitlab.com/2016/11/02/cve-2016-9086-patches/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94136

Scores

CVSS v3 6.5
EPSS 0.1349
EPSS Percentile 94.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (46)
gitlab/gitlab 8.9.0
gitlab/gitlab 8.9.1
gitlab/gitlab 8.9.2
gitlab/gitlab 8.9.3
gitlab/gitlab 8.9.4
gitlab/gitlab 8.9.5
gitlab/gitlab 8.9.6
gitlab/gitlab 8.9.7
gitlab/gitlab 8.9.8
gitlab/gitlab 8.9.9
... and 36 more
Published Nov 03, 2016
Tracked Since Feb 18, 2026