FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- vulnerabilities

Affected packages
17.3.0 <= gitlab-ce < 17.3.2
17.2.0 <= gitlab-ce < 17.2.5
8.14.0 <= gitlab-ce < 17.1.7
17.3.0 <= gitlab-ee < 17.3.2
17.2.0 <= gitlab-ee < 17.2.5
8.14.0 <= gitlab-ee < 17.1.7

Details

VuXML ID bcc8b21e-7122-11ef-bece-2cf05da270f3
Discovery 2024-09-11
Entry 2024-09-12

Gitlab reports:

Execute environment stop actions as the owner of the stop action job

Prevent code injection in Product Analytics funnels YAML

SSRF via Dependency Proxy

Denial of Service via sending a large glm_source parameter

CI_JOB_TOKEN can be used to obtain GitLab session token

Variables from settings are not overwritten by PEP if a template is included

Guests can disclose the full source code of projects using custom group-level templates

IdentitiesController allows linking of arbitrary unclaimed provider identities

Open redirect in repo/tree/:id endpoint can lead to account takeover through broken OAuth flow

Open redirect in release permanent links can lead to account takeover through broken OAuth flow

Guest user with Admin group member permission can edit custom role to gain other permissions

Exposure of protected and masked CI/CD variables by abusing on-demand DAST

Credentials disclosed when repository mirroring fails

Commit information visible through release atom endpoint for guest users

Dependency Proxy Credentials are Logged in Plaintext in graphql Logs

User Application can spoof the redirect url

Group Developers can view group runners information

References

CVE Name CVE-2024-2743
CVE Name CVE-2024-4283
CVE Name CVE-2024-4472
CVE Name CVE-2024-4612
CVE Name CVE-2024-4660
CVE Name CVE-2024-5435
CVE Name CVE-2024-6389
CVE Name CVE-2024-6446
CVE Name CVE-2024-6678
CVE Name CVE-2024-6685
CVE Name CVE-2024-8124
CVE Name CVE-2024-8311
CVE Name CVE-2024-8631
CVE Name CVE-2024-8635
CVE Name CVE-2024-8640
CVE Name CVE-2024-8641
URL https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/