CVE-2022-0123
https://notcve.org/view.php?id=CVE-2022-0123
28 Mar 2022 — An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services. Se ha detectado un problema afectando las versiones de GitLab anteriores a 14.4.5, entre la 14.5.0 y la 14.5.3, y entre la 14.6.0 y la 14.6.1. GitLab no comprueba los certificados SSL para algunos de los servicios ex... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0123.json • CWE-295: Improper Certificate Validation •
CVE-2022-0738
https://notcve.org/view.php?id=CVE-2022-0738
28 Mar 2022 — An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions. Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 14.6 anteriores a 14.6.5, todas las versiones a partir de la 14.7 anteriores a 14.7.4, todas las versiones a partir de la 14.8 anterior... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0738.json • CWE-522: Insufficiently Protected Credentials •
CVE-2022-0751
https://notcve.org/view.php?id=CVE-2022-0751
28 Mar 2022 — Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands Una visualización imprecisa de los archivos Snippet que contienen caracteres especiales en todas las versiones de GitLab CE/EE permite a un atacante crear Snippets con contenido engañoso que podría engañar a usuarios desprevenidos para que ejecuten comandos arbitrario • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0751.json •
CVE-2022-0371
https://notcve.org/view.php?id=CVE-2022-0371
28 Mar 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 11.4 anteriores a 14.5.4, todas las versiones a partir de la 14.6 anteriores a 14... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0371.json •
CVE-2022-0090
https://notcve.org/view.php?id=CVE-2022-0090
18 Jan 2022 — An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI. Se ha detectado un problema que afecta a versiones de GitLab anteriores a la 14.4.5, entre la 14.5.0 y la 14.5.3, y entre la 14.6.0 y la 14.6.1. GitLab está configurado de forma que no ignora las referencias... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0090.json • CWE-269: Improper Privilege Management •
CVE-2022-0093
https://notcve.org/view.php?id=CVE-2022-0093
18 Jan 2022 — An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds. Se ha detectado un problema que afecta a versiones de GitLab anteriores a 14.4.5, entre 14.5.0 y 14.5.3, y entre 14.6.0 y 14.6.1. GitLab permite que un usuario con una contraseña caducada acceda a información confidencial mediante canales RSS • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0093.json •
CVE-2022-0154
https://notcve.org/view.php?id=CVE-2022-0154
18 Jan 2022 — An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account. Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 7.7 anteriores a 14.4.5, a todas las versiones a partir de la 14.5.0 ante... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0154.json • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-0124
https://notcve.org/view.php?id=CVE-2022-0124
18 Jan 2022 — An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack. Se ha detectado un problema que afecta a las versiones de GitLab anteriores a 14.4.5, entre 14.5.0 y 14.5.3, y entre 14.6.0 y 14.6.1. La integración de Gitlab con Slack comprueba incorrectamente las entradas de los usuarios y permite que se diseñen URLs malic... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0124.json • CWE-116: Improper Encoding or Escaping of Output •
CVE-2021-39927
https://notcve.org/view.php?id=CVE-2021-39927
18 Jan 2022 — Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443 Las protecciones contra la falsificación de solicitudes del lado del servidor en las versiones de GitLab CE/EE entre 8.4 y 14.4.4, entre 14.5.0 y 14.5.2, y entre 14.6.0 y 14.6.1 fallaban en la protección contra los at... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39927.json • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2021-39935
https://notcve.org/view.php?id=CVE-2021-39935
13 Dec 2021 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 10.5 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. Los... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39935.json • CWE-918: Server-Side Request Forgery (SSRF) •