CVE-2023-3904 – Improper Validation of Specified Type of Input in GitLab
https://notcve.org/view.php?id=CVE-2023-3904
15 Dec 2023 — An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards. Se ha descubierto un problema en GitLab EE que afecta a todas las versiones anteriores a 16.4.4, todas las versiones anteriores a 16.5 anteriores a 16.5.4, todas las versiones anteriores a 16.6 anteriores a 16.6.2. Ha sido... • https://gitlab.com/gitlab-org/gitlab/-/issues/418226 • CWE-284: Improper Access Control CWE-1287: Improper Validation of Specified Type of Input •
CVE-2023-5061 – Missing Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-5061
15 Dec 2023 — An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API. Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 9.3 anteriores a 16.4.4, todas las versiones desde 16.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.... • https://gitlab.com/gitlab-org/gitlab/-/issues/425521 • CWE-285: Improper Authorization CWE-862: Missing Authorization •
CVE-2023-6051 – Improper Control of Generation of Code ('Code Injection') in GitLab
https://notcve.org/view.php?id=CVE-2023-6051
15 Dec 2023 — An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.4.4, todas las versiones desde 15.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.2. La integridad del archivo pu... • https://gitlab.com/gitlab-org/gitlab/-/issues/431345 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-3511 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-3511
15 Dec 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of. Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 8.17 anteriores a 16.4.4, todas las versiones desde 16.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.2.... • https://gitlab.com/gitlab-org/gitlab/-/issues/416961 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
CVE-2023-5332 – Dependency on Vulnerable Third-Party Component in GitLab
https://notcve.org/view.php?id=CVE-2023-5332
04 Dec 2023 — Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE. El parche en la librería de terceros Consul requiere que 'enable-script-checks' esté configurado en False. • https://gitlab.com/gitlab-org/omnibus-gitlab/-/issues/8171 • CWE-16: Configuration CWE-1395: Dependency on Vulnerable Third-Party Component •
CVE-2023-4317 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-4317
01 Dec 2023 — An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a user with the Developer role to update a pipeline schedule from an unprotected branch to a protected branch. Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 9.2 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anter... • https://gitlab.com/gitlab-org/gitlab/-/issues/421846 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
CVE-2023-4658 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-4658
01 Dec 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group. Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 8.13 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 1... • https://gitlab.com/gitlab-org/gitlab/-/issues/423835 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
CVE-2023-4912 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2023-4912
01 Dec 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input. Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 10.5 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anteriores a ... • https://gitlab.com/gitlab-org/gitlab/-/issues/424882 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2023-5226 – Improper Control of Generation of Code ('Code Injection') in GitLab
https://notcve.org/view.php?id=CVE-2023-5226
01 Dec 2023 — An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI. Se ha descubierto un problema en GitLab que afecta a todas las versiones anteriores a 16.4.3, todas las versiones a partir de 16.5 anteriores a 16.5.3, todas las versiones a partir... • https://gitlab.com/gitlab-org/gitlab/-/issues/426400 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-3246 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2023-3246
06 Nov 2023 — An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor. Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones anteriores a 16.3.6, todas las versiones desde 16.4 anteriores a 16.4.2, todas las versiones desde 16.5 anteriores a 16.5.1, lo que permite a los atacantes bloquear el procesador de trabajos... • https://gitlab.com/gitlab-org/gitlab/-/issues/415371 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •