Vulnerabilities patched in GitLab Community Edition and Enterprise Edition (advisories.ncsc.nl)
- Multiple vulnerabilities fixed in GitLab CE/EE.
- Affects versions up to 18.10.7, 18.11.4, 19.0.1.
- Issues include DoS, access control bypass, and identity spoofing.
"GitLab has fixed multiple vulnerabilities in Community Edition and Enterprise Edition. Affected versions: 12.7 to before 18.10.7, 18.11 to before 18.11.4, and 19.0 to before 19.0.1. The vulnerabilities involve authentication, authorization, and validation. Issues include denial of service via insufficient validation, unauthorized access to sensitive deployment data by developer users, identity spoofing in Duo AI workflows, bypassing group flow constraints, enumeration of private projects, and unauthorized access to CI data. CVE-2026-2710 was withdrawn."
no comments yet.