FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2025-02-02 08:34:31 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
bcc8b21e-7122-11ef-bece-2cf05da270f3Gitlab -- vulnerabilities

Gitlab reports:

Execute environment stop actions as the owner of the stop action job

Prevent code injection in Product Analytics funnels YAML

SSRF via Dependency Proxy

Denial of Service via sending a large glm_source parameter

CI_JOB_TOKEN can be used to obtain GitLab session token

Variables from settings are not overwritten by PEP if a template is included

Guests can disclose the full source code of projects using custom group-level templates

IdentitiesController allows linking of arbitrary unclaimed provider identities

Open redirect in repo/tree/:id endpoint can lead to account takeover through broken OAuth flow

Open redirect in release permanent links can lead to account takeover through broken OAuth flow

Guest user with Admin group member permission can edit custom role to gain other permissions

Exposure of protected and masked CI/CD variables by abusing on-demand DAST

Credentials disclosed when repository mirroring fails

Commit information visible through release atom endpoint for guest users

Dependency Proxy Credentials are Logged in Plaintext in graphql Logs

User Application can spoof the redirect url

Group Developers can view group runners information


Discovery 2024-09-11
Entry 2024-09-12
gitlab-ce
gitlab-ee
>= 17.3.0 lt 17.3.2

>= 17.2.0 lt 17.2.5

>= 8.14.0 lt 17.1.7

CVE-2024-6678
CVE-2024-8640
CVE-2024-8635
CVE-2024-8124
CVE-2024-8641
CVE-2024-8311
CVE-2024-4660
CVE-2024-4283
CVE-2024-4612
CVE-2024-8631
CVE-2024-2743
CVE-2024-5435
CVE-2024-6389
CVE-2024-4472
CVE-2024-6446
CVE-2024-6685
https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/