
CVE-2024-6595 – Uncontrolled Search Path Element in GitLab
https://notcve.org/view.php?id=CVE-2024-6595
17 Jul 2024 — An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.8 anterior a la 16.11.6, desde la 17.0 anterior a la 17.0.4 y desde la 17.1 anterior a la 17.1.2 donde era posible cargar un paquete NPM con conflictos datos del paquete. • https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem • CWE-427: Uncontrolled Search Path Element CWE-434: Unrestricted Upload of File with Dangerous Type CWE-451: User Interface (UI) Misrepresentation of Critical Information •

CVE-2024-6385 – Improper Access Control in GitLab
https://notcve.org/view.php?id=CVE-2024-6385
11 Jul 2024 — An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.8 anterior a la 16.11.6, desde la 17.0 anterior a la 17.0.4 y desde la 17.1 anterior a la 17.1.2, lo que permite a un atacante activar una pipeline como otro ... • https://gitlab.com/gitlab-org/gitlab/-/issues/469217 • CWE-284: Improper Access Control •

CVE-2024-1493 – Uncontrolled Resource Consumption in GitLab
https://notcve.org/view.php?id=CVE-2024-1493
26 Jun 2024 — An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 9.2 anterior a la 16.11.5, desde la 17.0 anterior a la 17.0.3 y desde la 17.1 anterior a la 17.1.1, con la lógica de procesamiento... • https://gitlab.com/gitlab-org/gitlab/-/issues/441806 • CWE-400: Uncontrolled Resource Consumption CWE-1333: Inefficient Regular Expression Complexity •

CVE-2024-1816 – Uncontrolled Resource Consumption in GitLab
https://notcve.org/view.php?id=CVE-2024-1816
26 Jun 2024 — An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 12.0 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que permite que un atacante provoque una denegación de servicio utilizando un a... • https://gitlab.com/gitlab-org/gitlab/-/issues/442852 • CWE-400: Uncontrolled Resource Consumption •

CVE-2024-3115 – Exposure of Sensitive Information to an Unauthorized Actor in GitLab
https://notcve.org/view.php?id=CVE-2024-3115
26 Jun 2024 — An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat. Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 16.0 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que permite a un atacante acceder a problemas y epics sin tener una Sesión ... • https://gitlab.com/gitlab-org/gitlab/-/issues/452548 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-862: Missing Authorization •

CVE-2024-4011 – Improper Access Control in GitLab
https://notcve.org/view.php?id=CVE-2024-4011
26 Jun 2024 — An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 16.1 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que permite que quienes no son miembros del proyecto promuevan resultados clave a los objetivos. • https://gitlab.com/gitlab-org/gitlab/-/issues/457235 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •

CVE-2024-4557 – Uncontrolled Resource Consumption in GitLab
https://notcve.org/view.php?id=CVE-2024-4557
26 Jun 2024 — Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline. Se han descubierto múltiples condiciones de denegación de servicio (DoS) en GitLab CE/EE que afectan a todas las versiones desde 1.0 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que p... • https://gitlab.com/gitlab-org/gitlab/-/issues/460517 • CWE-400: Uncontrolled Resource Consumption •

CVE-2024-5655 – Improper Access Control in GitLab
https://notcve.org/view.php?id=CVE-2024-5655
26 Jun 2024 — An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.8 anterior a la 16.11.5, desde la 17.0 anterior a la 17.0.3 y desde la 17.1 anterior a la 17.1.1, lo que permite a un atacante activar una canalización como o... • https://github.com/VulnResearcher/CVE-2024-5655-Gitlab-CSRF-GraphQL • CWE-284: Improper Access Control •

CVE-2024-1736 – Uncontrolled Resource Consumption in GitLab
https://notcve.org/view.php?id=CVE-2024-1736
12 Jun 2024 — An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's CI/CD pipeline editor could allow for denial of service attacks through maliciously crafted configuration files. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.10.7, desde 16.11 anterior a 16.11.4 y desde 17.0 anterior a 17.0.2. Una vulnerabilidad en el editor de canalización ... • https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#redos-in-ci-interpolation-fix-bypass • CWE-400: Uncontrolled Resource Consumption CWE-1333: Inefficient Regular Expression Complexity •

CVE-2024-1495 – Uncontrolled Resource Consumption in GitLab
https://notcve.org/view.php?id=CVE-2024-1495
12 Jun 2024 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 13.1 anterior a 16.10.7, desde 16.11 anterior a 16.11.4 y desde 17.0 anterior a 17.0.2. Era posible que un atacante provocara una denegación de servicio uti... • https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#redos-in-gomod-dependency-linker • CWE-400: Uncontrolled Resource Consumption CWE-1333: Inefficient Regular Expression Complexity •