
CVE-2023-5356 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-5356
12 Jan 2024 — Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user. Verificaciones de autorización incorrectas en GitLab CE/EE desde todas las versiones desde 8.13 anteriores a 16.5.6, todas las versiones desde 16.6 anteriores a 16.6.4, todas las versiones desde 16.7 anteriores a 16.7.2, pe... • https://gitlab.com/gitlab-org/gitlab/-/issues/427154 • CWE-863: Incorrect Authorization •

CVE-2023-6955 – Missing Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-6955
12 Jan 2024 — An improper access control vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group. Existe una vulnerabilidad de control de acceso inadecuado en GitLab Remote Development que afecta a todas las versiones anteriores a 16.5.6, 16.6 anterior a 16.6.4 y 16.7 anterior a 16.7.2. Esta condición permite a un atacante... • https://gitlab.com/gitlab-org/gitlab/-/issues/432188 • CWE-284: Improper Access Control CWE-668: Exposure of Resource to Wrong Sphere CWE-862: Missing Authorization •

CVE-2023-3904 – Improper Validation of Specified Type of Input in GitLab
https://notcve.org/view.php?id=CVE-2023-3904
15 Dec 2023 — An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards. Se ha descubierto un problema en GitLab EE que afecta a todas las versiones anteriores a 16.4.4, todas las versiones anteriores a 16.5 anteriores a 16.5.4, todas las versiones anteriores a 16.6 anteriores a 16.6.2. Ha sido... • https://gitlab.com/gitlab-org/gitlab/-/issues/418226 • CWE-284: Improper Access Control CWE-1287: Improper Validation of Specified Type of Input •

CVE-2023-6051 – Improper Control of Generation of Code ('Code Injection') in GitLab
https://notcve.org/view.php?id=CVE-2023-6051
15 Dec 2023 — An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.4.4, todas las versiones desde 15.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.2. La integridad del archivo pu... • https://gitlab.com/gitlab-org/gitlab/-/issues/431345 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2023-4658 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-4658
01 Dec 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group. Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 8.13 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 1... • https://gitlab.com/gitlab-org/gitlab/-/issues/423835 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •

CVE-2023-5226 – Improper Control of Generation of Code ('Code Injection') in GitLab
https://notcve.org/view.php?id=CVE-2023-5226
01 Dec 2023 — An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI. Se ha descubierto un problema en GitLab que afecta a todas las versiones anteriores a 16.4.3, todas las versiones a partir de 16.5 anteriores a 16.5.3, todas las versiones a partir... • https://gitlab.com/gitlab-org/gitlab/-/issues/426400 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2023-3246 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2023-3246
06 Nov 2023 — An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor. Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones anteriores a 16.3.6, todas las versiones desde 16.4 anteriores a 16.4.2, todas las versiones desde 16.5 anteriores a 16.5.1, lo que permite a los atacantes bloquear el procesador de trabajos... • https://gitlab.com/gitlab-org/gitlab/-/issues/415371 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2023-3917 – Improper Validation of Specified Type of Input in GitLab
https://notcve.org/view.php?id=CVE-2023-3917
29 Sep 2023 — Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail. La Denegación de Servicio en pipelines afectan a todas las versiones de Gitlab EE y CE anteriores a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1 permite que un atacante provoque fallas en los pipelines. • https://gitlab.com/gitlab-org/gitlab/-/issues/417896 • CWE-20: Improper Input Validation CWE-1287: Improper Validation of Specified Type of Input •

CVE-2023-3914 – Incorrect User Management in GitLab
https://notcve.org/view.php?id=CVE-2023-3914
29 Sep 2023 — A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects. Un error de lógica de negocios en GitLab EE que afecta a todas las versiones anteriores a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1 permite el acceso a proyectos internos. Una cuenta de servicio no se elimina cuando se elimina un espacio d... • https://gitlab.com/gitlab-org/gitlab/-/issues/418115 • CWE-286: Incorrect User Management CWE-840: Business Logic Errors •

CVE-2023-1279 – URL Redirection to Untrusted Site in GitLab
https://notcve.org/view.php?id=CVE-2023-1279
01 Sep 2023 — An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project. Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de 4.1 y antes de 16.1.5, todas las versiones a partir de 16.2 y antes de 16.2.5, todas las versiones a partir de 16.3 y antes de 16.3.1, donde es posible crear... • https://gitlab.com/gitlab-org/gitlab/-/issues/395437 • CWE-138: Improper Neutralization of Special Elements CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •