CVE-2022-1428
https://notcve.org/view.php?id=CVE-2022-1428
11 May 2022 — An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced. Se ha detectado un problema en GitLab afectando a todas las versiones anteriores a 14.8.6, a todas las versiones a partir de la 14.9 anteriores a 14.9.4 y todas las versiones a partir de la 14.10 anteriores a... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1428.json • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2022-1426
https://notcve.org/view.php?id=CVE-2022-1426
11 May 2022 — An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token. Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 12.6 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anterio... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1426.json • CWE-287: Improper Authentication •
CVE-2022-1352
https://notcve.org/view.php?id=CVE-2022-1352
11 May 2022 — Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members. Debido a una vulnerabilidad de referencia directa a objetos insegura en Gitlab EE/CE afectando a todas las versiones desde 11.0 anteriores a 14.8.6, 14.9 anteriore... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1352.json • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2022-1433
https://notcve.org/view.php?id=CVE-2022-1433
11 May 2022 — An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute. Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 14.4 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anteriores a 1... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1433.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-1545
https://notcve.org/view.php?id=CVE-2022-1545
11 May 2022 — It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note. Era posible divulgar detalles de notas confidenciales creadas por medio de la API en Gitlab CE/EE, afectando a todas las versiones desde la 13.2 hasta la 14.8.6, 14.9 anteriores a 14.9.4 y 14.10 anteriores a 14.10.1, si un miembro del proyecto no autorizado era... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1545.json •
CVE-2022-1417
https://notcve.org/view.php?id=CVE-2022-1417
10 May 2022 — Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs Un control de acceso inadecuado en GitLab CE/EE que afecta a todas las versiones a partir de la 8.12 antes de la 14.8.6, a todas las versiones a partir de la 14.9 antes de la 14.9.4, y a todas las versiones a partir de... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1417.json • CWE-863: Incorrect Authorization •
CVE-2022-1431
https://notcve.org/view.php?id=CVE-2022-1431
10 May 2022 — An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption. Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de 12.10 anteriores a 14.8.6, todas las versiones a partir de 14.9 anteriores a 14.9.4, todas l... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1431.json • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-0477
https://notcve.org/view.php?id=CVE-2022-0477
25 Apr 2022 — An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions. Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 11.9 anteriores a 14.5.4, todas las versiones a partir de l... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0477.json •
CVE-2022-1157
https://notcve.org/view.php?id=CVE-2022-1157
11 Apr 2022 — Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged Una falta de saneo de los mensajes de excepción registrados en todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2 de GitLab CE/EE causa el registro de posibles valores confidenciales en URLs no válidas • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1157.json • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2022-1193
https://notcve.org/view.php?id=CVE-2022-1193
11 Apr 2022 — Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances Un control de acceso inadecuado en las versiones 10.7 anterior a 14.7.7, 14.8 anterior a 14.8.5 y 14.9 anterior a 14.9.2 de GitLab CE/EE permite a un actor malintencionado obtener detalles del último commit de un proyecto privado a través de Merge Requests en de... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1193.json • CWE-863: Incorrect Authorization •