CVE-2022-1981
https://notcve.org/view.php?id=CVE-2022-1981
01 Jul 2022 — An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list. Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de la 12.2 anteriore... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1981.json • CWE-863: Incorrect Authorization •
CVE-2022-1983
https://notcve.org/view.php?id=CVE-2022-1983
01 Jul 2022 — Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured. Una autorización incorrecta en GitLab EE afectando a todas las versiones desde la 10.7 anteriores a 14.10.5, 15.0 anteriores a 15.0.4 y 15.1 anteriores a 15.1.1, permitía a un ataca... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1983.json • CWE-863: Incorrect Authorization •
CVE-2022-2227
https://notcve.org/view.php?id=CVE-2022-2227
01 Jul 2022 — Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions Un control de acceso inapropiado en la API de trabajos del corredor en GitLab CE/EE afectando a todas las versiones anteriores a 14.10.5, 15.0 anteriores a 15.0.4, y 15.1 anteriores a 15.1.1, permite a un mantenedor anterior de un proy... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2227.json • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2022-2250
https://notcve.org/view.php?id=CVE-2022-2250
01 Jul 2022 — An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL. Una vulnerabilidad de redireccionamiento abierto en GitLab EE/CE afectando a todas las versiones desde la 11.1 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite a un atacante redirigir a usuarios a una ubicación arbitraria si confían en la UR... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2250.json • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2022-1680
https://notcve.org/view.php?id=CVE-2022-1680
06 Jun 2022 — An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in t... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1680.json •
CVE-2022-1944
https://notcve.org/view.php?id=CVE-2022-1944
06 Jun 2022 — When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs Cuando la función está configurada, una autorización inapropiada en el Terminal Web Interactivo en GitLab CE/EE que afectando a todas las versiones desde la 11.3 anteriores a 14.9.5, 14.10 anteriores a 14.10.4, y 15.0 ant... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.json • CWE-863: Incorrect Authorization •
CVE-2022-1821
https://notcve.org/view.php?id=CVE-2022-1821
06 Jun 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group. Se ha detectado un problema en GitLab CE/EE afectando todas las versiones a partir de 10.8 anteriores a 14.9.5, todas las versiones a partir de la 14.10 anteriores a 14.10.4, todas las versiones a partir de la 15.0 anterior... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1821.json •
CVE-2022-1936
https://notcve.org/view.php?id=CVE-2022-1936
06 Jun 2022 — Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured Una autorización incorrecta en GitLab EE, afectando todas las versiones a partir de 12.0 anteriores a 14.9.5, todas las versiones a partir de 14.10 anteriores a 14.10.4 y todas ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1936.json • CWE-863: Incorrect Authorization •
CVE-2022-1935
https://notcve.org/view.php?id=CVE-2022-1935
06 Jun 2022 — Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured Una autorización incorrecta en GitLab EE afectando todas las versiones a partir de 12.0 anteriores a 14.9.5, todas las versiones a partir de la 14.10 anteriores a 14.10.4, toda... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1935.json • CWE-863: Incorrect Authorization •
CVE-2022-1423
https://notcve.org/view.php?id=CVE-2022-1423
19 May 2022 — Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches Un control de acceso inapropiado en el mecanismo de caché CI/CD en GitLab CE/EE afectando a todas las versiones a partir de la 1.0.2 anteriores a 14.8.6, todas las ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1423.json • CWE-862: Missing Authorization •