FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-09-07 14:16:01 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
acb4eab6-3f6d-11ef-8657-001b217b3468Gitlab -- vulnerabilities

Gitlab reports:

An attacker can run pipeline jobs as an arbitrary user

Developer user with admin_compliance_framework permission can change group URL

Admin push rules custom role allows creation of project level deploy token

Package registry vulnerable to manifest confusion

User with admin_group_member permission can ban group members

Subdomain takeover in GitLab Pages


Discovery 2024-07-10
Entry 2024-07-11
gitlab-ce
gitlab-ee
ge 17.1.0 lt 17.1.2

ge 17.0.0 lt 17.0.4

ge 11.8.0 lt 16.11.6

CVE-2024-6385
CVE-2024-5257
CVE-2024-5470
CVE-2024-6595
CVE-2024-2880
CVE-2024-5528
https://about.gitlab.com/releases/2024/07/10/patch-release-gitlab-17-1-2-released/
b2caae55-dc38-11ee-96dc-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

Bypassing CODEOWNERS approval allowing to steal protected variables

Guest with manage group access tokens can rotate and see group access token with owner permissions


Discovery 2024-03-06
Entry 2024-03-07
gitlab-ce
ge 16.9.0 lt 16.9.2

ge 16.8.0 lt 16.8.4

ge 11.3.0 lt 16.7.7

CVE-2024-0199
CVE-2024-1299
https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/
fbc2c629-0dc5-11ef-9850-001b217b3468Gitlab -- vulnerabilities

Gitlab reports:

ReDoS in branch search when using wildcards

ReDoS in markdown render pipeline

Redos on Discord integrations

Redos on Google Chat Integration

Denial of Service Attack via Pin Menu

DoS by filtering tags and branches via the API

MR approval via CSRF in SAML SSO

Banned user from groups can read issues updates via the api

Require confirmation before linking JWT identity

View confidential issues title and description of any public project via export

SSRF via Github importer


Discovery 2024-05-08
Entry 2024-05-09
gitlab-ce
gitlab-ee
ge 16.11.0 lt 16.11.2

ge 16.10.0 lt 16.10.5

ge 10.6.0 lt 16.9.7

CVE-2024-2878
CVE-2024-2651
CVE-2023-6682
CVE-2023-6688
CVE-2024-2454
CVE-2024-4539
CVE-2024-4597
CVE-2024-1539
CVE-2024-1211
CVE-2024-3976
CVE-2023-6195
https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released/
f848ef90-1848-11ef-9850-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

1-click account takeover via XSS in the code editor in gitlab.com

A DOS vulnerability in the 'description' field of the runner

CSRF via K8s cluster-integration

Using Set Pipeline Status of a Commit API incorrectly create a new pipeline when SHA and pipeline_id did not match

Redos on wiki render API/Page

Resource exhaustion and denial of service with test_report API calls

Guest user can view dependency lists of private projects through job artifacts

Stored XSS via PDFjs


Discovery 2024-05-22
Entry 2024-05-22
gitlab-ce
gitlab-ee
ge 17.0.0 lt 17.0.1

ge 16.11.0 lt 16.11.3

ge 11.11 lt 16.10.6

CVE-2024-4835
CVE-2024-2874
CVE-2023-7045
CVE-2023-6502
CVE-2024-1947
CVE-2024-4367
https://about.gitlab.com/releases/2024/05/22/patch-release-gitlab-17-0-1-released/
03bf5157-d145-11ee-acee-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

Stored-XSS in user's profile page

User with "admin_group_members" permission can invite other groups to gain owner access

ReDoS issue in the Codeowners reference extractor

LDAP user can reset password using secondary email and login using direct authentication

Bypassing group ip restriction settings to access environment details of projects through Environments/Operations Dashboard

Users with the Guest role can change Custom dashboard projects settings for projects in the victim group

Group member with sub-maintainer role can change title of shared private deploy keys

Bypassing approvals of CODEOWNERS


Discovery 2024-02-21
Entry 2024-02-22
gitlab-ce
ge 16.9.0 lt 16.9.1

ge 16.8.0 lt 16.8.3

ge 11.3.0 lt 16.7.6

CVE-2024-1451
CVE-2023-6477
CVE-2023-6736
CVE-2024-1525
CVE-2023-4895
CVE-2024-0861
CVE-2023-3509
CVE-2024-0410
https://about.gitlab.com/releases/2024/02/21/security-release-gitlab-16-9-1-released/
b857606c-0266-11ef-8681-001b217b3468Gitlab -- vulnerabilities

Gitlab reports:

GitLab account takeover, under certain conditions, when using Bitbucket as an OAuth provider

Path Traversal leads to DoS and Restricted File Read

Unauthenticated ReDoS in FileFinder when using wildcard filters in project file search

Personal Access Token scopes not honoured by GraphQL subscriptions

Domain based restrictions bypass using a crafted email address


Discovery 2024-04-24
Entry 2024-04-24
gitlab-ce
gitlab-ee
ge 16.11.0 lt 16.11.1

ge 16.10.0 lt 16.10.4

ge 7.8.0 lt 16.9.6

CVE-2024-4024
CVE-2024-2434
CVE-2024-2829
CVE-2024-4006
CVE-2024-1347
https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/
92cd1c03-2940-11ef-bc02-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

ReDoS in gomod dependency linker

ReDoS in CI interpolation (fix bypass)

ReDoS in Asana integration issue mapping when webhook is called

XSS and content injection when viewing raw XHTML files on iOS devices

Missing agentk request validation could cause KAS to panic


Discovery 2024-06-12
Entry 2024-06-13
gitlab-ce
gitlab-ee
ge 17.0.0 lt 17.0.2

ge 16.11.0 lt 16.11.4

ge 5.1 lt 16.10.7

CVE-2024-1495
CVE-2024-1736
CVE-2024-1963
CVE-2024-4201
CVE-2024-5469
https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/
dad6294c-f7c1-11ee-bb77-001b217b3468Gitlab -- Patch Release: 16.10.2, 16.9.4, 16.8.6

Gitlab reports:

Stored XSS injected in diff viewer

Stored XSS via autocomplete results

Redos on Integrations Chat Messages

Redos During Parse Junit Test Report


Discovery 2024-04-10
Entry 2024-04-11
gitlab-ce
ge 16.10.0 lt 16.10.2

ge 16.9.0 lt 16.9.4

< 16.8.6

CVE-2024-3092
CVE-2024-2279
CVE-2023-6489
CVE-2023-6678
https://about.gitlab.com/releases/2024/04/10/patch-release-gitlab-16-10-2-released/
d2992bc2-ed18-11ee-96dc-001b217b3468Gitlab -- vulnerabilities

Gitlab reports:

Stored-XSS injected in Wiki page via Banzai pipeline

DOS using crafted emojis


Discovery 2024-03-27
Entry 2024-03-28
gitlab-ce
ge 16.10.0 lt 16.10.1

ge 16.9.0 lt 16.9.3

< 16.8.5

CVE-2023-6371
CVE-2024-2818
https://about.gitlab.com/releases/2024/03/27/security-release-gitlab-16-10-1-released/
24c88add-4a3e-11ef-86d7-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

XSS via the Maven Dependency Proxy

Project level analytics settings leaked in DOM

Reports can access and download job artifacts despite use of settings to prevent it

Direct Transfer - Authorised project/group exports are accessible to other users

Bypassing tag check and branch check through imports

Project Import/Export - Make project/group export files hidden to everyone except user who initiated it


Discovery 2024-07-24
Entry 2024-07-25
gitlab-ce
gitlab-ee
ge 17.2.0 lt 17.2.1

ge 17.1.0 lt 17.1.3

ge 12.0.0 lt 17.0.5

CVE-2024-5067
CVE-2024-7057
CVE-2024-0231
https://about.gitlab.com/releases/2024/07/24/patch-release-gitlab-17-2-1-released/
589de937-343f-11ef-8a7b-001b217b3468Gitlab -- Vulnerabilities

Gitlab reports:

Run pipelines as any user

Stored XSS injected in imported project's commit notes

CSRF on GraphQL API IntrospectionQuery

Remove search results from public projects with unauthorized repos

Cross window forgery in user application OAuth flow

Project maintainers can bypass group's merge request approval policy

ReDoS via custom built markdown page

Private job artifacts can be accessed by any user

Security fixes for banzai pipeline

ReDoS in dependency linker

Denial of service using a crafted OpenAPI file

Merge request title disclosure

Access issues and epics without having an SSO session

Non project member can promote key results to objectives


Discovery 2024-06-26
Entry 2024-06-27
gitlab-ce
gitlab-ee
ge 17.1.0 lt 17.1.1

ge 17.0.0 lt 17.0.3

ge 1.0.0 lt 16.11.5

CVE-2024-5655
CVE-2024-4901
CVE-2024-4994
CVE-2024-6323
CVE-2024-2177
CVE-2024-5430
CVE-2024-4025
CVE-2024-3959
CVE-2024-4557
CVE-2024-1493
CVE-2024-1816
CVE-2024-2191
CVE-2024-3115
CVE-2024-4011
https://about.gitlab.com/releases/2024/06/26/patch-release-gitlab-17-1-1-released/