![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-5106 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-5106
02 Oct 2023 — An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports. Se ha descubierto un problema en Ultimate-licensed GitLab EE que afecta a todas las versiones desde 13.12 anteriores a 16.2.8, 16.3.0 anteriores a 16.3.5 y 16.4.0 anteriores a 16.4.1 y que podría permitir a un atacante hacerse pasar por usua... • https://gitlab.com/gitlab-org/gitlab/-/commit/67039cfcae80b8fc0496f79be88714873cd169b3 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-3922 – URL Redirection to Untrusted Site ('Open Redirect') in GitLab
https://notcve.org/view.php?id=CVE-2023-3922
29 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page. Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 8.15 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5, todas las versiones desde 16.4 anteriores a 16.4.1. Fue posible secuestrar alg... • https://gitlab.com/gitlab-org/gitlab/-/issues/394770 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-5198 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-5198
29 Sep 2023 — An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys. Se descubrió un problema en GitLab que afecta a todas las versiones anteriores a 16.2.7, todas las versiones desde 16.3 anteriores a 16.3.5 y todas las versiones desde 16.4 anteriores a 16.4.1. Era posible que un miembro eliminado del proye... • https://gitlab.com/gitlab-org/gitlab/-/issues/416957 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-0989 – Improper Ownership Management in GitLab
https://notcve.org/view.php?id=CVE-2023-0989
29 Sep 2023 — An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration. Un problema de divulgación de información en GitLab CE/EE que afecta a todas las versiones a partir de 13.11 anterior a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1 permite a un atacante extraer variables CI/CD no... • https://gitlab.com/gitlab-org/gitlab/-/issues/417275 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-282: Improper Ownership Management •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-2233 – Missing Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-2233
29 Sep 2023 — An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects. Se descubrió un problema de autorización incorrecta en GitLab CE/EE que afecta a todas las versiones desde 11.8 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5 y todas las versiones desde 16.... • https://gitlab.com/gitlab-org/gitlab/-/issues/408359 • CWE-285: Improper Authorization CWE-862: Missing Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-3115 – Incorrect User Management in GitLab
https://notcve.org/view.php?id=CVE-2023-3115
29 Sep 2023 — An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories. Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 11.11 anteriores a 16.2.8, 16.3 anteriores a 16.3.5 y 16.4 anteriores a 16.4.1. Las restricciones de Inicio de Sesión Único no se apli... • https://gitlab.com/gitlab-org/gitlab/-/issues/414367 • CWE-284: Improper Access Control CWE-286: Incorrect User Management •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-3920 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-3920
29 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation. Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 11.2 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5, todas las versiones desde 16.4 anteriores a ... • https://gitlab.com/gitlab-org/gitlab/-/issues/417481 • CWE-345: Insufficient Verification of Data Authenticity CWE-863: Incorrect Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-3917 – Improper Validation of Specified Type of Input in GitLab
https://notcve.org/view.php?id=CVE-2023-3917
29 Sep 2023 — Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail. La Denegación de Servicio en pipelines afectan a todas las versiones de Gitlab EE y CE anteriores a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1 permite que un atacante provoque fallas en los pipelines. • https://gitlab.com/gitlab-org/gitlab/-/issues/417896 • CWE-20: Improper Input Validation CWE-1287: Improper Validation of Specified Type of Input •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-3914 – Incorrect User Management in GitLab
https://notcve.org/view.php?id=CVE-2023-3914
29 Sep 2023 — A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects. Un error de lógica de negocios en GitLab EE que afecta a todas las versiones anteriores a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1 permite el acceso a proyectos internos. Una cuenta de servicio no se elimina cuando se elimina un espacio d... • https://gitlab.com/gitlab-org/gitlab/-/issues/418115 • CWE-286: Incorrect User Management CWE-840: Business Logic Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-3906 – Improper Validation of Specified Type of Input in GitLab
https://notcve.org/view.php?id=CVE-2023-3906
29 Sep 2023 — An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy. Un problema de validación de entrada en el proxy de activos en GitLab EE, que afectó a todas las versiones desde 12.3 anterior a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1, permitió a un atacante autenticado crear URL de imágenes que omitían el activo apoder... • https://gitlab.com/gitlab-org/gitlab/-/issues/419213 • CWE-20: Improper Input Validation CWE-1287: Improper Validation of Specified Type of Input CWE-1333: Inefficient Regular Expression Complexity •