CVE-2023-5963 |
|
Medium |
Nov 06, 2023 |
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.
more...
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.
less...
|
15.6.6, 15.6.4, 15.2.2, 15.1.4, 14.8.5, 14.7.7, 14.2.6
|
CVE-2023-5198 |
BDSA-2023-2583 |
Medium |
Sep 29, 2023 |
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting
more...
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.
less...
|
15.6.6, 15.6.4, 15.2.2, 15.1.4, 14.8.5, 14.7.7, 14.2.6, 13.6.7, 13.5.6, 13.7.3
|
CVE-2023-5106 |
|
High |
Oct 02, 2023 |
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 p
more...
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.
less...
|
15.6.6, 15.6.4, 15.2.2, 15.1.4, 14.8.5, 14.7.7, 14.2.6
|
CVE-2023-5009 |
|
Critical |
Sep 19, 2023 |
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It w
more...
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.
less...
|
15.6.6, 15.6.4, 15.2.2, 15.1.4, 14.8.5, 14.7.7, 14.2.6
|
CVE-2023-4700 |
|
Medium |
Nov 06, 2023 |
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a
more...
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.
less...
|
15.6.6, 15.6.4, 15.2.2, 15.1.4, 14.8.5, 14.7.7
|
CVE-2023-4647 |
BDSA-2023-2313 |
High |
Sep 01, 2023 |
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all vers
more...
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.
less...
|
15.6.6, 15.6.4, 15.2.2
|
CVE-2023-4630 |
BDSA-2023-2312 |
Medium |
Sep 11, 2023 |
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all vers
more...
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.
less...
|
15.6.6, 15.6.4, 15.2.2, 15.1.4, 14.8.5, 14.7.7, 14.2.6, 13.6.7, 13.5.6, 13.7.3
|
CVE-2023-4379 |
|
High |
Nov 09, 2023 |
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Co
more...
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
less...
|
15.6.6, 15.6.4
|
CVE-2023-4378 |
BDSA-2023-2309 |
Medium |
Sep 01, 2023 |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, al
more...
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365.
less...
|
15.6.6, 15.6.4, 15.2.2, 15.1.4, 14.8.5, 14.7.7, 14.2.6, 13.6.7, 13.5.6, 13.7.3
|
CVE-2023-3994 |
BDSA-2023-2041 |
High |
Aug 02, 2023 |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all
more...
An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.
less...
|
15.6.6, 15.6.4, 15.2.2, 15.1.4, 14.8.5, 14.7.7, 14.2.6, 13.6.7, 13.5.6, 13.7.3
|