CVE-2022-1936
https://notcve.org/view.php?id=CVE-2022-1936
06 Jun 2022 — Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured Una autorización incorrecta en GitLab EE, afectando todas las versiones a partir de 12.0 anteriores a 14.9.5, todas las versiones a partir de 14.10 anteriores a 14.10.4 y todas ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1936.json • CWE-863: Incorrect Authorization •
CVE-2022-1940
https://notcve.org/view.php?id=CVE-2022-1940
06 Jun 2022 — A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues Una vulnerabilidad de tipo almacenado en la integración de Jira en GitLab EE afectando a todas las versiones desde la 13.11 anteriores a 14.9.5, 14.10 anteriores a 14.10.4 y 15.0 anteriores a 15.0.1, permite a un a... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1940.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-1935
https://notcve.org/view.php?id=CVE-2022-1935
06 Jun 2022 — Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured Una autorización incorrecta en GitLab EE afectando todas las versiones a partir de 12.0 anteriores a 14.9.5, todas las versiones a partir de la 14.10 anteriores a 14.10.4, toda... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1935.json • CWE-863: Incorrect Authorization •
CVE-2022-1423
https://notcve.org/view.php?id=CVE-2022-1423
19 May 2022 — Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches Un control de acceso inapropiado en el mecanismo de caché CI/CD en GitLab CE/EE afectando a todas las versiones a partir de la 1.0.2 anteriores a 14.8.6, todas las ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1423.json • CWE-862: Missing Authorization •
CVE-2022-1413
https://notcve.org/view.php?id=CVE-2022-1413
19 May 2022 — Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface Una falta de enmascaramiento de entradas en GitLab CE/EE, afectando a todas las versiones a partir de la 1.0.2 anteriores a 14.8.6, todas las versiones a partir de la 14.9.0 anteriores a 14.9.4 y todas las versiones a partir de la 14.10.0 ant... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1413.json • CWE-522: Insufficiently Protected Credentials •
CVE-2022-1416
https://notcve.org/view.php?id=CVE-2022-1416
19 May 2022 — Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling Una falta de saneo de datos en los mensajes de error de Pipeline en GitLab CE/EE, afectando a todas las versiones a partir de la 1.0.2 anteriores a 14.8.6, todas las versiones a partir de la 14.9.0 anteriores a 14.9.4 y todas l... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1416.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-1124
https://notcve.org/view.php?id=CVE-2022-1124
11 May 2022 — An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled Se ha detectado un problema de autorización incorrecta en GitLab CE/EE afectando a todas las versiones anteriores a 14.8.6, todas las versiones de la 14.9.0 anteriores a 14.9.4 y 14.10.0, y que permite a miembros del proyecto invitados acceder al registro de seguimiento ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json • CWE-863: Incorrect Authorization •
CVE-2022-1510
https://notcve.org/view.php?id=CVE-2022-1510
11 May 2022 — An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption. Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 13.9 anteriores a 14.8.6, a todas las versiones a partir de la 14.9 anteri... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1510.json • CWE-1333: Inefficient Regular Expression Complexity •
CVE-2022-1460
https://notcve.org/view.php?id=CVE-2022-1460
11 May 2022 — An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user. Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 9.2 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anteriores a 14.9.4, to... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1460.json • CWE-863: Incorrect Authorization •
CVE-2022-1406
https://notcve.org/view.php?id=CVE-2022-1406
11 May 2022 — Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project Una comprobación de entrada inapropiada en GitLab CE/EE afectando a todas las versiones desde la 8.12 anteriores a 14.8.6, todas las versiones desde la 14.9.0 anteriores a 14.9.4 y 14.10.0, permite a un desarrollador leer variables de CI/CD protegidas de grupos o... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1406.json • CWE-20: Improper Input Validation •