CVE-2022-1124
https://notcve.org/view.php?id=CVE-2022-1124
11 May 2022 — An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled Se ha detectado un problema de autorización incorrecta en GitLab CE/EE afectando a todas las versiones anteriores a 14.8.6, todas las versiones de la 14.9.0 anteriores a 14.9.4 y 14.10.0, y que permite a miembros del proyecto invitados acceder al registro de seguimiento ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json • CWE-863: Incorrect Authorization •
CVE-2022-1460
https://notcve.org/view.php?id=CVE-2022-1460
11 May 2022 — An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user. Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 9.2 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anteriores a 14.9.4, to... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1460.json • CWE-863: Incorrect Authorization •
CVE-2022-1406
https://notcve.org/view.php?id=CVE-2022-1406
11 May 2022 — Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project Una comprobación de entrada inapropiada en GitLab CE/EE afectando a todas las versiones desde la 8.12 anteriores a 14.8.6, todas las versiones desde la 14.9.0 anteriores a 14.9.4 y 14.10.0, permite a un desarrollador leer variables de CI/CD protegidas de grupos o... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1406.json • CWE-20: Improper Input Validation •
CVE-2022-1428
https://notcve.org/view.php?id=CVE-2022-1428
11 May 2022 — An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced. Se ha detectado un problema en GitLab afectando a todas las versiones anteriores a 14.8.6, a todas las versiones a partir de la 14.9 anteriores a 14.9.4 y todas las versiones a partir de la 14.10 anteriores a... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1428.json • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2022-1417
https://notcve.org/view.php?id=CVE-2022-1417
10 May 2022 — Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs Un control de acceso inadecuado en GitLab CE/EE que afecta a todas las versiones a partir de la 8.12 antes de la 14.8.6, a todas las versiones a partir de la 14.9 antes de la 14.9.4, y a todas las versiones a partir de... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1417.json • CWE-863: Incorrect Authorization •
CVE-2022-1157
https://notcve.org/view.php?id=CVE-2022-1157
11 Apr 2022 — Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged Una falta de saneo de los mensajes de excepción registrados en todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2 de GitLab CE/EE causa el registro de posibles valores confidenciales en URLs no válidas • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1157.json • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2022-1190
https://notcve.org/view.php?id=CVE-2022-1190
04 Apr 2022 — Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc. Un manejo inapropiado de la entrada del usuario en GitLab CE/EE versiones 8.3 anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, permitía a un atacante explotar un ataque de tipo XSS almacenado al abusar de las referencias de hitos de vari... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1190.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-1121
https://notcve.org/view.php?id=CVE-2022-1121
04 Apr 2022 — A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption. Una falta de tiempos de espera apropiados en GitLab Pages incluidos en GitLab CE/EE todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, permite a un atacante causar un consumo no limitado de recursos • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1121.json • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2022-1120
https://notcve.org/view.php?id=CVE-2022-1120
04 Apr 2022 — Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration. Una falta de filtrado en un mensaje de error en GitLab CE/EE afectando a todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, expone información confidencial cuando falla una directiva de inclusión en la configuración de CI/CD • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1120.json • CWE-209: Generation of Error Message Containing Sensitive Information •
CVE-2022-1099
https://notcve.org/view.php?id=CVE-2022-1099
04 Apr 2022 — Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab La adición de un número muy grande de etiquetas a un corredor en GitLab CE/EE afectando a todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2 permite a un atacante afectar al rendimiento de GitLab • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1099.json • CWE-400: Uncontrolled Resource Consumption •