Improper access expiration date validation in GitLab version >=8.11.0-rc6+ allows user to have access to projects with expiration.
Published at: October 07, 2020 at 10:15AM
View on website
Improper access expiration date validation in GitLab version >=8.11.0-rc6+ allows user to have access to projects with expiration.
Published at: October 07, 2020 at 10:15AM
View on website
In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query
Published at: October 07, 2020 at 10:15AM
View on website
Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.
Published at: October 07, 2020 at 10:15AM
View on website
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
Published at: October 07, 2020 at 10:15AM
View on website
A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows host, via DOCKER_AUTH_CONFIG build variable.
Published at: October 07, 2020 at 10:15AM
View on website