CVE-2024-9387 – URL Redirection to Untrusted Site ('Open Redirect') in GitLab
https://notcve.org/view.php?id=CVE-2024-9387
An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint. • https://gitlab.com/gitlab-org/gitlab/-/issues/496659 https://hackerone.com/reports/2732235 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2024-10043 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2024-10043
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure. • https://gitlab.com/gitlab-org/gitlab/-/issues/499577 https://hackerone.com/reports/2774817 • CWE-863: Incorrect Authorization •
CVE-2024-11274 – URL Redirection to Untrusted Site ('Open Redirect') in GitLab
https://notcve.org/view.php?id=CVE-2024-11274
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration. • https://gitlab.com/gitlab-org/gitlab/-/issues/504707 https://hackerone.com/reports/2813673 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2024-12570 – Privilege Context Switching Error in GitLab
https://notcve.org/view.php?id=CVE-2024-12570
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim. • https://gitlab.com/gitlab-org/gitlab/-/issues/494694 https://hackerone.com/reports/2724948 • CWE-270: Privilege Context Switching Error •
CVE-2024-12292 – Insertion of Sensitive Information into Log File in GitLab
https://notcve.org/view.php?id=CVE-2024-12292
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs. • https://gitlab.com/gitlab-org/gitlab/-/issues/475211 • CWE-532: Insertion of Sensitive Information into Log File •