CVE-2024-8312 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
https://notcve.org/view.php?id=CVE-2024-8312
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS. Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.10 hasta la 17.3.6, la 17.4 hasta la 17.4.3 y la 17.5 hasta la 17.5.1. Un atacante podría inyectar HTML en el campo de búsqueda global en una vista de diferencias, lo que provocaría un XSS. • https://gitlab.com/gitlab-org/gitlab/-/issues/481819 https://hackerone.com/reports/2659386 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-8970 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2024-8970
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances. • https://gitlab.com/gitlab-org/gitlab/-/issues/490916 https://hackerone.com/reports/2724948 • CWE-863: Incorrect Authorization •
CVE-2024-5005 – Incorrect Provision of Specified Functionality in GitLab
https://notcve.org/view.php?id=CVE-2024-5005
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API. • https://gitlab.com/gitlab-org/gitlab/-/issues/462108 https://hackerone.com/reports/2501461 • CWE-684: Incorrect Provision of Specified Functionality •
CVE-2024-9164 – Missing Authentication for Critical Function in GitLab
https://notcve.org/view.php?id=CVE-2024-9164
An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches. • https://gitlab.com/gitlab-org/gitlab/-/issues/493946 https://hackerone.com/reports/2711204 • CWE-306: Missing Authentication for Critical Function •
CVE-2024-6530 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
https://notcve.org/view.php?id=CVE-2024-6530
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances. • https://gitlab.com/gitlab-org/gitlab/-/issues/471049 https://hackerone.com/reports/2567533 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •