CVE-2023-3950 – Cleartext Storage of Sensitive Information in GitLab
https://notcve.org/view.php?id=CVE-2023-3950
01 Sep 2023 — An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it. Un problema de divulgación de información en GitLab EE que afectaba a todas las versiones desde la 16.2 hasta la 16.2.5, y desde la 16.3 hasta la 16.3.1 permitía a otros propietarios de grupo ver la clave pública de un... • https://gitlab.com/gitlab-org/gitlab/-/issues/419675 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2023-4018 – Direct Request ('Forced Browsing') in GitLab
https://notcve.org/view.php?id=CVE-2023-4018
01 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects. • https://gitlab.com/gitlab-org/gitlab/-/issues/420301 • CWE-284: Improper Access Control CWE-425: Direct Request ('Forced Browsing') •
CVE-2023-4378 – Insertion of Sensitive Information Into Sent Data in GitLab
https://notcve.org/view.php?id=CVE-2023-4378
01 Sep 2023 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365. • https://gitlab.com/gitlab-org/gitlab/-/issues/422134 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-201: Insertion of Sensitive Information Into Sent Data •
CVE-2023-4647 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2023-4647
01 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances. • https://gitlab.com/gitlab-org/gitlab/-/issues/414502 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2022-4343 – Exposure of Sensitive Information to an Unauthorized Actor in GitLab
https://notcve.org/view.php?id=CVE-2022-4343
01 Sep 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile. Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de 13.12 y antes de 16.1.5, todas las versiones a partir de 16.2 y antes de 16.2.5, todas las versiones a partir de 16.3 y antes de 16.3.1, en el que un miembro de... • https://gitlab.com/gitlab-org/gitlab/-/issues/385124 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-0120 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-0120
01 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user. Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 10.0 antes de la 16.1.5, todas las versiones a partir de la 16.2 antes de la 16.2.5 y todas las versiones a partir de la 16.3 an... • https://gitlab.com/gitlab-org/gitlab/-/issues/387531 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
CVE-2023-1279 – URL Redirection to Untrusted Site in GitLab
https://notcve.org/view.php?id=CVE-2023-1279
01 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project. Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de 4.1 y antes de 16.1.5, todas las versiones a partir de 16.2 y antes de 16.2.5, todas las versiones a partir de 16.3 y antes de 16.3.1, donde es posible crear... • https://gitlab.com/gitlab-org/gitlab/-/issues/395437 • CWE-138: Improper Neutralization of Special Elements CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2023-1555 – Missing Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-1555
01 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API. Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 15.2 antes de la 16.1.5, todas las versiones a partir de la 16.2 antes de la 16.2.5 y todas las versiones a partir de la 16.3 antes de la 16.3.1. Un usuario baneado a nivel de espacio ... • https://gitlab.com/gitlab-org/gitlab/-/issues/398587 • CWE-262: Not Using Password Aging CWE-284: Improper Access Control •
CVE-2023-3205 – Inefficient Regular Expression Complexity in GitLab
https://notcve.org/view.php?id=CVE-2023-3205
01 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content. Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 15.11 antes de la 16.1.5, a todas las versiones a partir de la 16.2 antes de la 16.2.5 y a todas las versiones a partir de la 16.3 a... • https://gitlab.com/gitlab-org/gitlab/-/issues/415067 • CWE-400: Uncontrolled Resource Consumption CWE-1333: Inefficient Regular Expression Complexity •
CVE-2023-3915 – Incorrect Execution-Assigned Permissions in GitLab
https://notcve.org/view.php?id=CVE-2023-3915
01 Sep 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects. Se ha descubierto un problema en GitLab EE que afecta a ... • https://gitlab.com/gitlab-org/gitlab/-/issues/417664 • CWE-279: Incorrect Execution-Assigned Permissions CWE-732: Incorrect Permission Assignment for Critical Resource •