FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-09-13 07:13:07 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
589de937-343f-11ef-8a7b-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

Run pipelines as any user

Stored XSS injected in imported project's commit notes

CSRF on GraphQL API IntrospectionQuery

Remove search results from public projects with unauthorized repos

Cross window forgery in user application OAuth flow

Project maintainers can bypass group's merge request approval policy

ReDoS via custom built markdown page

Private job artifacts can be accessed by any user

Security fixes for banzai pipeline

ReDoS in dependency linker

Denial of service using a crafted OpenAPI file

Merge request title disclosure

Access issues and epics without having an SSO session

Non project member can promote key results to objectives


Discovery 2024-06-26
Entry 2024-06-27
gitlab-ce
gitlab-ee
>= 17.1.0 lt 17.1.1

>= 17.0.0 lt 17.0.3

>= 1.0.0 lt 16.11.5

CVE-2024-5655
CVE-2024-4901
CVE-2024-4994
CVE-2024-6323
CVE-2024-2177
CVE-2024-5430
CVE-2024-4025
CVE-2024-3959
CVE-2024-4557
CVE-2024-1493
CVE-2024-1816
CVE-2024-2191
CVE-2024-3115
CVE-2024-4011
https://about.gitlab.com/releases/2024/06/26/patch-release-gitlab-17-1-1-released/
92cd1c03-2940-11ef-bc02-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

ReDoS in gomod dependency linker

ReDoS in CI interpolation (fix bypass)

ReDoS in Asana integration issue mapping when webhook is called

XSS and content injection when viewing raw XHTML files on iOS devices

Missing agentk request validation could cause KAS to panic


Discovery 2024-06-12
Entry 2024-06-13
gitlab-ce
gitlab-ee
>= 17.0.0 lt 17.0.2

>= 16.11.0 lt 16.11.4

>= 5.1 lt 16.10.7

CVE-2024-1495
CVE-2024-1736
CVE-2024-1963
CVE-2024-4201
CVE-2024-5469
https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/
b950a83b-789e-11e8-8545-d8cb8abf62ddGitlab -- multiple vulnerabilities

Gitlab reports:

Wiki XSS

Sanitize gem updates

XSS in url_for(params)

Content injection via username

Activity feed publicly displaying internal project names

Persistent XSS in charts


Discovery 2018-06-25
Entry 2018-06-25
gitlab
>= 11.0.0 lt 11.0.1

>= 10.8.0 lt 10.8.5

>= 4.1 lt 10.7.6

CVE-2018-12606
CVE-2018-3740
CVE-2018-12605
CVE-2018-12607
https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/
fbc2c629-0dc5-11ef-9850-001b217b3468Gitlab -- vulnerabilities

Gitlab reports:

ReDoS in branch search when using wildcards

ReDoS in markdown render pipeline

Redos on Discord integrations

Redos on Google Chat Integration

Denial of Service Attack via Pin Menu

DoS by filtering tags and branches via the API

MR approval via CSRF in SAML SSO

Banned user from groups can read issues updates via the api

Require confirmation before linking JWT identity

View confidential issues title and description of any public project via export

SSRF via Github importer


Discovery 2024-05-08
Entry 2024-05-09
gitlab-ce
gitlab-ee
>= 16.11.0 lt 16.11.2

>= 16.10.0 lt 16.10.5

>= 10.6.0 lt 16.9.7

CVE-2024-2878
CVE-2024-2651
CVE-2023-6682
CVE-2023-6688
CVE-2024-2454
CVE-2024-4539
CVE-2024-4597
CVE-2024-1539
CVE-2024-1211
CVE-2024-3976
CVE-2023-6195
https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released/
8fc615cc-8a66-11e8-8c75-d8cb8abf62ddGitlab -- Remote Code Execution Vulnerability in GitLab Projects Import

Gitlab reports:

Remote Code Execution Vulnerability in GitLab Projects Import


Discovery 2018-07-17
Entry 2018-07-18
gitlab-ce
gitlab
>= 11.0.0 lt 11.0.4

>= 10.8.0 lt 10.8.6

>= 8.9.0 lt 10.7.7

CVE-2018-14364
https://about.gitlab.com/2018/07/17/critical-security-release-gitlab-11-dot-0-dot-4-released/
b857606c-0266-11ef-8681-001b217b3468Gitlab -- vulnerabilities

Gitlab reports:

GitLab account takeover, under certain conditions, when using Bitbucket as an OAuth provider

Path Traversal leads to DoS and Restricted File Read

Unauthenticated ReDoS in FileFinder when using wildcard filters in project file search

Personal Access Token scopes not honoured by GraphQL subscriptions

Domain based restrictions bypass using a crafted email address


Discovery 2024-04-24
Entry 2024-04-24
gitlab-ce
gitlab-ee
>= 16.11.0 lt 16.11.1

>= 16.10.0 lt 16.10.4

>= 7.8.0 lt 16.9.6

CVE-2024-4024
CVE-2024-2434
CVE-2024-2829
CVE-2024-4006
CVE-2024-1347
https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/
9dfe61c8-4d15-11e8-8f2f-d8cb8abf62ddGitlab -- multiple vulnerabilities

GitLab reports:

Persistent XSS in Move Issue using project namespace

Download Archive allowing unauthorized private repo access

Mattermost Updates


Discovery 2018-04-30
Entry 2018-05-01
gitlab
>= 10.7.0 lt 10.7.2

>= 10.6.0 lt 10.6.5

>= 9.5.0 lt 10.5.8

CVE-2018-10379
https://about.gitlab.com/2018/04/30/security-release-gitlab-10-dot-7-dot-2-released
49ef501c-62b6-11ef-bba5-2cf05da270f3Gitlab -- vulnerabilities

Gitlab reports:

The GitLab Web Interface Does Not Guarantee Information Integrity When Downloading Source Code from Releases

Denial of Service by importing maliciously crafted GitHub repository

Prompt injection in "Resolve Vulnerabilty" results in arbitrary command execution in victim's pipeline

An unauthorized user can perform certain actions through GraphQL after a group owner enables IP restrictions


Discovery 2024-08-21
Entry 2024-08-25
gitlab-ce
gitlab-ee
>= 17.3.0 lt 17.3.1

>= 17.2.0 lt 17.2.4

>= 8.2.0 lt 17.1.6

CVE-2024-6502
CVE-2024-8041
CVE-2024-7110
CVE-2024-3127
https://about.gitlab.com/releases/2024/08/21/patch-release-gitlab-17-3-1-released/
9557dc72-64da-11e8-bc32-d8cb8abf62ddGitlab -- multiple vulnerabilities

GitLab reports:

Removing public deploy keys regression

Users can update their password without entering current password

Persistent XSS - Selecting users as allowed merge request approvers

Persistent XSS - Multiple locations of user selection drop downs

include directive in .gitlab-ci.yml allows SSRF requests

Permissions issue in Merge Requests Create Service

Arbitrary assignment of project fields using "Import project"


Discovery 2018-05-29
Entry 2018-05-31
gitlab
>= 10.8.0 lt 10.8.2

>= 10.7.0 lt 10.7.5

>= 1.0 lt 10.6.6

https://about.gitlab.com/2018/05/29/security-release-gitlab-10-dot-8-dot-2-released/