Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2023-5332
Disclosure Date: December 04, 2023 (last updated December 08, 2023)
Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.
0
Attacker Value
Unknown
CVE-2023-4379
Disclosure Date: November 09, 2023 (last updated November 17, 2023)
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
0
Attacker Value
Unknown
CVE-2023-5106
Disclosure Date: October 02, 2023 (last updated October 09, 2023)
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.
0
Attacker Value
Unknown
CVE-2023-5207
Disclosure Date: September 30, 2023 (last updated October 09, 2023)
A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.
0
Attacker Value
Unknown
CVE-2023-3413
Disclosure Date: September 29, 2023 (last updated October 09, 2023)
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.
0
Attacker Value
Unknown
CVE-2023-5198
Disclosure Date: September 29, 2023 (last updated October 09, 2023)
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.
0
Attacker Value
Unknown
CVE-2023-3922
Disclosure Date: September 29, 2023 (last updated October 09, 2023)
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.
0
Attacker Value
Unknown
CVE-2023-4532
Disclosure Date: September 29, 2023 (last updated October 09, 2023)
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.
0
Attacker Value
Unknown
CVE-2023-3979
Disclosure Date: September 29, 2023 (last updated December 22, 2024)
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.
0
Attacker Value
Unknown
CVE-2023-3920
Disclosure Date: September 29, 2023 (last updated October 08, 2023)
An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.
0