CVE-2023-3950 – Cleartext Storage of Sensitive Information in GitLab
https://notcve.org/view.php?id=CVE-2023-3950
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it. Un problema de divulgación de información en GitLab EE que afectaba a todas las versiones desde la 16.2 hasta la 16.2.5, y desde la 16.3 hasta la 16.3.1 permitía a otros propietarios de grupo ver la clave pública de un destino de transmisión de eventos de auditoría de Google Cloud Logging, si estaba configurado. Ahora los propietarios solo pueden escribir la clave, no leerla. • https://gitlab.com/gitlab-org/gitlab/-/issues/419675 https://hackerone.com/reports/2079154 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2023-4018 – Direct Request ('Forced Browsing') in GitLab
https://notcve.org/view.php?id=CVE-2023-4018
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects. • https://gitlab.com/gitlab-org/gitlab/-/issues/420301 https://hackerone.com/reports/2083440 • CWE-284: Improper Access Control CWE-425: Direct Request ('Forced Browsing') •
CVE-2023-4378 – Insertion of Sensitive Information Into Sent Data in GitLab
https://notcve.org/view.php?id=CVE-2023-4378
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365. • https://gitlab.com/gitlab-org/gitlab/-/issues/422134 https://hackerone.com/reports/2104591 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-201: Insertion of Sensitive Information Into Sent Data •
CVE-2023-4647 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2023-4647
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances. • https://gitlab.com/gitlab-org/gitlab/-/issues/414502 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2022-4343 – Exposure of Sensitive Information to an Unauthorized Actor in GitLab
https://notcve.org/view.php?id=CVE-2022-4343
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile. Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de 13.12 y antes de 16.1.5, todas las versiones a partir de 16.2 y antes de 16.2.5, todas las versiones a partir de 16.3 y antes de 16.3.1, en el que un miembro del proyecto puede filtrar las credenciales almacenadas del perfil del sitio. • https://gitlab.com/gitlab-org/gitlab/-/issues/385124 https://hackerone.com/reports/1767797 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •