FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-09-13 07:13:07 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
24c88add-4a3e-11ef-86d7-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

XSS via the Maven Dependency Proxy

Project level analytics settings leaked in DOM

Reports can access and download job artifacts despite use of settings to prevent it

Direct Transfer - Authorised project/group exports are accessible to other users

Bypassing tag check and branch check through imports

Project Import/Export - Make project/group export files hidden to everyone except user who initiated it


Discovery 2024-07-24
Entry 2024-07-25
gitlab-ce
gitlab-ee
>= 17.2.0 lt 17.2.1

>= 17.1.0 lt 17.1.3

>= 12.0.0 lt 17.0.5

CVE-2024-5067
CVE-2024-7057
CVE-2024-0231
https://about.gitlab.com/releases/2024/07/24/patch-release-gitlab-17-2-1-released/
92cd1c03-2940-11ef-bc02-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

ReDoS in gomod dependency linker

ReDoS in CI interpolation (fix bypass)

ReDoS in Asana integration issue mapping when webhook is called

XSS and content injection when viewing raw XHTML files on iOS devices

Missing agentk request validation could cause KAS to panic


Discovery 2024-06-12
Entry 2024-06-13
gitlab-ce
gitlab-ee
>= 17.0.0 lt 17.0.2

>= 16.11.0 lt 16.11.4

>= 5.1 lt 16.10.7

CVE-2024-1495
CVE-2024-1736
CVE-2024-1963
CVE-2024-4201
CVE-2024-5469
https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/
589de937-343f-11ef-8a7b-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

Run pipelines as any user

Stored XSS injected in imported project's commit notes

CSRF on GraphQL API IntrospectionQuery

Remove search results from public projects with unauthorized repos

Cross window forgery in user application OAuth flow

Project maintainers can bypass group's merge request approval policy

ReDoS via custom built markdown page

Private job artifacts can be accessed by any user

Security fixes for banzai pipeline

ReDoS in dependency linker

Denial of service using a crafted OpenAPI file

Merge request title disclosure

Access issues and epics without having an SSO session

Non project member can promote key results to objectives


Discovery 2024-06-26
Entry 2024-06-27
gitlab-ce
gitlab-ee
>= 17.1.0 lt 17.1.1

>= 17.0.0 lt 17.0.3

>= 1.0.0 lt 16.11.5

CVE-2024-5655
CVE-2024-4901
CVE-2024-4994
CVE-2024-6323
CVE-2024-2177
CVE-2024-5430
CVE-2024-4025
CVE-2024-3959
CVE-2024-4557
CVE-2024-1493
CVE-2024-1816
CVE-2024-2191
CVE-2024-3115
CVE-2024-4011
https://about.gitlab.com/releases/2024/06/26/patch-release-gitlab-17-1-1-released/
49ef501c-62b6-11ef-bba5-2cf05da270f3Gitlab -- vulnerabilities

Gitlab reports:

The GitLab Web Interface Does Not Guarantee Information Integrity When Downloading Source Code from Releases

Denial of Service by importing maliciously crafted GitHub repository

Prompt injection in "Resolve Vulnerabilty" results in arbitrary command execution in victim's pipeline

An unauthorized user can perform certain actions through GraphQL after a group owner enables IP restrictions


Discovery 2024-08-21
Entry 2024-08-25
gitlab-ce
gitlab-ee
>= 17.3.0 lt 17.3.1

>= 17.2.0 lt 17.2.4

>= 8.2.0 lt 17.1.6

CVE-2024-6502
CVE-2024-8041
CVE-2024-7110
CVE-2024-3127
https://about.gitlab.com/releases/2024/08/21/patch-release-gitlab-17-3-1-released/
729008b9-54bf-11ef-a61b-2cf05da270f3Gitlab -- Vulnerabilities

Gitlab reports:

Privilege Escalation via LFS Tokens Granting Unrestricted Repository Access

Cross project access of Security policy bot

Advanced search ReDOS in highlight for code results

Denial of Service via banzai pipeline

Denial of service using adoc files

ReDoS in RefMatcher when matching branch names using wildcards

Path encoding can cause the Web interface to not render diffs correctly

XSS while viewing raw XHTML files through API

Ambiguous tag name exploitation

Logs disclosings potentially sensitive data in query params

Password bypass on approvals using policy projects

ReDoS when parsing git push

Webhook deletion audit log can preserve auth credentials


Discovery 2024-08-07
Entry 2024-08-07
gitlab-ce
gitlab-ee
>= 17.2.0 lt 17.2.2

>= 17.1.0 lt 17.1.4

>= 12.0.0 lt 17.0.6

CVE-2024-3035
CVE-2024-6356
CVE-2024-5423
CVE-2024-4210
CVE-2024-2800
CVE-2024-6329
CVE-2024-4207
CVE-2024-3958
CVE-2024-4784
CVE-2024-3114
CVE-2024-7586
https://about.gitlab.com/releases/2024/08/07/patch-release-gitlab-17-2-2-released/
f848ef90-1848-11ef-9850-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

1-click account takeover via XSS in the code editor in gitlab.com

A DOS vulnerability in the 'description' field of the runner

CSRF via K8s cluster-integration

Using Set Pipeline Status of a Commit API incorrectly create a new pipeline when SHA and pipeline_id did not match

Redos on wiki render API/Page

Resource exhaustion and denial of service with test_report API calls

Guest user can view dependency lists of private projects through job artifacts

Stored XSS via PDFjs


Discovery 2024-05-22
Entry 2024-05-22
gitlab-ce
gitlab-ee
>= 17.0.0 lt 17.0.1

>= 16.11.0 lt 16.11.3

>= 11.11 lt 16.10.6

CVE-2024-4835
CVE-2024-2874
CVE-2023-7045
CVE-2023-6502
CVE-2024-1947
CVE-2024-4367
https://about.gitlab.com/releases/2024/05/22/patch-release-gitlab-17-0-1-released/
acb4eab6-3f6d-11ef-8657-001b217b3468Gitlab -- vulnerabilities

Gitlab reports:

An attacker can run pipeline jobs as an arbitrary user

Developer user with admin_compliance_framework permission can change group URL

Admin push rules custom role allows creation of project level deploy token

Package registry vulnerable to manifest confusion

User with admin_group_member permission can ban group members

Subdomain takeover in GitLab Pages


Discovery 2024-07-10
Entry 2024-07-11
gitlab-ce
gitlab-ee
>= 17.1.0 lt 17.1.2

>= 17.0.0 lt 17.0.4

>= 11.8.0 lt 16.11.6

CVE-2024-6385
CVE-2024-5257
CVE-2024-5470
CVE-2024-6595
CVE-2024-2880
CVE-2024-5528
https://about.gitlab.com/releases/2024/07/10/patch-release-gitlab-17-1-2-released/