GitLab 12.5 < 17.2.9 / 17.3 < 17.3.5 / 17.4 < 17.4.2 (CVE-2024-9164)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: Gitlab reports: Run pipelines on arbitrary branches An attacker can impersonate arbitrary user SSRF in ...

Continue Reading
GitLab 11.6 < 17.2.9 / 17.3 < 17.3.5 / 17.4 < 17.4.2 (CVE-2024-8970)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: Gitlab reports: Run pipelines on arbitrary branches An attacker can impersonate arbitrary user SSRF in ...

Continue Reading
GitLab 11.4 < 17.2.9 / 17.3 < 17.3.5 / 17.4 < 17.4.2 (CVE-2024-5005)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: Gitlab reports: Run pipelines on arbitrary branches An attacker can impersonate arbitrary user SSRF in ...

Continue Reading
New Critical GitLab Vulnerability Could Allow Arbitrary CI/CD Pipeline Execution

GitLab has released security updates for Community Edition (CE) and Enterprise Edition (EE) to address eight security flaws, including a critical bug that could allow running Continuous Integration an ...

Continue Reading
FreeBSD : Gitlab — vulnerabilities (cc1ac01e-86b0-11ef-9369-2cf05da270f3)

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the cc1ac01e-86b0-11ef-9369-2cf05da270f3 advisor ...

Continue Reading
Gitlab — vulnerabilities

Gitlab reports: Run pipelines on arbitrary branches An attacker can impersonate arbitrary user SSRF in Analytics Dashboard Viewing diffs of MR with conflicts can be slow HTMLi in OAuth page Deploy Key ...

Continue Reading
API Gateways and API Protection: What’s the Difference?

Modern businesses are increasingly reliant on APIs. They are the building blocks facilitating data exchange and communication between disparate systems. Because of their prevalence and importance, the ...

Continue Reading
GitLab Enterprise Edition – Server-Side Request Forgery

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF...Read M ...

Continue Reading

Back to Main

Subscribe for the latest news: