CVE-2021-39908
https://notcve.org/view.php?id=CVE-2021-39908
01 Apr 2022 — In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI. En todas las versiones de GitLab CE/EE a partir de la 0.8.0 antes de la 14.2.6, en todas las versiones a partir de la 14.3 antes de la 14.3.4, y en todas las versiones a partir de la 14.4 antes de la 14.... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39908.json • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2022-0373
https://notcve.org/view.php?id=CVE-2022-0373
01 Apr 2022 — Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address Un control de acceso inapropiado en GitLab CE/EE versiones 12.4 a 14.5.4, 14.5 a 14.6.4 y 12.6 a 14.7.1, permite que personas que no son miembros del proyecto recuperen la dirección de correo electrónico del servicio de asistencia técnica • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0373.json •
CVE-2022-0390
https://notcve.org/view.php?id=CVE-2022-0390
01 Apr 2022 — Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard. Un control de acceso inapropiado en Gitlab CE/EE versiones 12.7 a 14.5.4, 14.6 a 14.6.4 y 14.7 a 14.7.1, permitía a personas que no eran miembros del proyecto recuperar los detalles de las incidencias cuando estaban vinculadas a un elemento del panel de control de vulnerabilidades • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0390.json • CWE-862: Missing Authorization •
CVE-2022-0489
https://notcve.org/view.php?id=CVE-2022-0489
01 Apr 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 8.15 . Era posible desencadenar un DOS usando la función de matemáticas con una fórmula específica en los comentarios de la edición • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0489.json • CWE-400: Uncontrolled Resource Consumption •
CVE-2021-4191 – GitLab GraphQL API User Enumeration
https://notcve.org/view.php?id=CVE-2021-4191
28 Mar 2022 — An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API. Se ha detectado un problema en GitLab CE/EE afectando las versiones 13.0 a 14.6.5, 14.7 a 14.7.4 y 14.8 a 14.8.2. Las instancias privadas de GitLab con registros restringidos pueden ser vulnerables a una enumeración de usuarios a usuarios no autenticados med... • https://github.com/K3ysTr0K3R/CVE-2021-4191-EXPLOIT •
CVE-2022-0283
https://notcve.org/view.php?id=CVE-2022-0283
28 Mar 2022 — An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL. Se ha detectado un problema afectando GitLab versiones anteriores a 13.5. Ha sido corregido una vulnerabilidad de redireccionamiento abierto en la integración de GitLab con Jira que podía causar que la aplicación web redirigiera la petición a la URL especificada por el ataca... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0283.json • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2022-0136
https://notcve.org/view.php?id=CVE-2022-0136
28 Mar 2022 — A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature. Se ha detectado una vulnerabilidad en GitLab versiones 10.5 a 14.5.4, 14.6 a 14.6.4 y 14.7 a 14.7.1. GitLab era vulnerable a un ataque de tipo SSRF ciego mediante la funcionalidad Project Import • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0136.json • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2021-39876
https://notcve.org/view.php?id=CVE-2021-39876
28 Mar 2022 — In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups. En todas las versiones de GitLab CE/EE desde versión 11.3, el endpoint para autocompletar la asignación divulga los miembros de los grupos privados • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39876.json • CWE-863: Incorrect Authorization •
CVE-2022-0488
https://notcve.org/view.php?id=CVE-2022-0488
28 Mar 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 8.10. Era posible desencadenar un tiempo de espera en una página con markdown al usar una cantidad específica de comillas de bloque • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0488.json • CWE-400: Uncontrolled Resource Consumption •
CVE-2022-0344
https://notcve.org/view.php?id=CVE-2022-0344
28 Mar 2022 — An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 10.0 anteriores a 14.5.4, todas las versiones a partir de la 10.1 anteriores a ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0344.json •