Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2023-5332

Disclosure Date: December 04, 2023 (last updated December 08, 2023)
Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.
Attacker Value
Unknown

CVE-2023-4379

Disclosure Date: November 09, 2023 (last updated November 17, 2023)
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
Attacker Value
Unknown

CVE-2023-5106

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.
Attacker Value
Unknown

CVE-2023-5207

Disclosure Date: September 30, 2023 (last updated October 09, 2023)
A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.
Attacker Value
Unknown

CVE-2023-3413

Disclosure Date: September 29, 2023 (last updated October 09, 2023)
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.
Attacker Value
Unknown

CVE-2023-5198

Disclosure Date: September 29, 2023 (last updated October 09, 2023)
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.
Attacker Value
Unknown

CVE-2023-3922

Disclosure Date: September 29, 2023 (last updated October 09, 2023)
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.
Attacker Value
Unknown

CVE-2023-4532

Disclosure Date: September 29, 2023 (last updated October 09, 2023)
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.
Attacker Value
Unknown

CVE-2023-3979

Disclosure Date: September 29, 2023 (last updated December 22, 2024)
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.
Attacker Value
Unknown

CVE-2023-3920

Disclosure Date: September 29, 2023 (last updated October 08, 2023)
An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.