
CVE-2022-0549
https://notcve.org/view.php?id=CVE-2022-0549
28 Mar 2022 — An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a 14.3.6, todas las versiones a partir de la 14.4 anteriores a 14.4.4, todas las versiones a ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0549.json •

CVE-2022-0735
https://notcve.org/view.php?id=CVE-2022-0735
28 Mar 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 12.10 anteriores a 14.6.5, todas las versiones a partir de la 14.7 anteriores a ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0735.json •

CVE-2022-0090
https://notcve.org/view.php?id=CVE-2022-0090
18 Jan 2022 — An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI. Se ha detectado un problema que afecta a versiones de GitLab anteriores a la 14.4.5, entre la 14.5.0 y la 14.5.3, y entre la 14.6.0 y la 14.6.1. GitLab está configurado de forma que no ignora las referencias... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0090.json • CWE-269: Improper Privilege Management •

CVE-2022-0093
https://notcve.org/view.php?id=CVE-2022-0093
18 Jan 2022 — An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds. Se ha detectado un problema que afecta a versiones de GitLab anteriores a 14.4.5, entre 14.5.0 y 14.5.3, y entre 14.6.0 y 14.6.1. GitLab permite que un usuario con una contraseña caducada acceda a información confidencial mediante canales RSS • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0093.json •

CVE-2022-0125
https://notcve.org/view.php?id=CVE-2022-0125
18 Jan 2022 — An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project. Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 12.0 anteriores a 14.4.5, todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, todas las versiones a par... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0125.json • CWE-862: Missing Authorization •

CVE-2022-0154
https://notcve.org/view.php?id=CVE-2022-0154
18 Jan 2022 — An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account. Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 7.7 anteriores a 14.4.5, a todas las versiones a partir de la 14.5.0 ante... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0154.json • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-0124
https://notcve.org/view.php?id=CVE-2022-0124
18 Jan 2022 — An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack. Se ha detectado un problema que afecta a las versiones de GitLab anteriores a 14.4.5, entre 14.5.0 y 14.5.3, y entre 14.6.0 y 14.6.1. La integración de Gitlab con Slack comprueba incorrectamente las entradas de los usuarios y permite que se diseñen URLs malic... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0124.json • CWE-116: Improper Encoding or Escaping of Output •

CVE-2022-0244
https://notcve.org/view.php?id=CVE-2022-0244
18 Jan 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file. Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 14.5. Una lectura arbitraria de archivos era posible al importar un grupo debido a un manejo incorrecto del archivo • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0244.json • CWE-552: Files or Directories Accessible to External Parties •

CVE-2022-0151
https://notcve.org/view.php?id=CVE-2022-0151
18 Jan 2022 — An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions. Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 12.10 anteriores a 14.4.5, todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, t... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0151.json •

CVE-2022-0152
https://notcve.org/view.php?id=CVE-2022-0152
18 Jan 2022 — An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API. Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 13.10 anteriores a 14.4.5, todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, todas las versiones a partir de la 14.6.0 ant... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0152.json • CWE-862: Missing Authorization •