In GitLab CE/EE versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, and starting from 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-8177 was detected. This vulnerability allows attackers to cause a Denial of Service by integrating a malicious Harbor registry. To address this issue, users must upgrade to GitLab CE/EE versions 17.4.5, 17.5.3, or 17.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8177.
Read more Developer ToolsIn GitLab CE/EE versions 16.11 prior to 17.4.5, 17.5 prior to 17.5.3, 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-11668 was detected. This vulnerability allows attackers to bypass authentication and access sensitive data through long-lasting connections. To fix this issue, users should upgrade GitLab CE/EE to versions 17.4.5, 17.5.3 or 17.6.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-11668.
Read more Developer ToolsIn GitLab CE/EE versions 16.9.8 prior to 17.4.5, 17.5 prior to 17.5.3, 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-11669 was detected. This vulnerability allows attackers to access sensitive data without proper authorization by exploiting certain security weaknesses in GitLab’s API. To fix this issue, users should upgrade GitLab CE/EE to versions 17.4.5, 17.5.3, or 17.6.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-11669.
Read more Developer ToolsIn GitLab CE/EE versions 13.2.4 prior to 17.4.5, 17.5 prior to 17.5.3, 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-11828 was detected. This vulnerability allows attackers to create a denial of service (DoS) condition by sending crafted API calls. To fix this issue, users should upgrade GitLab CE/EE to versions 17.4.5, 17.5.3 or 17.6.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11828.
Read more Developer ToolsIn GitLab CE/EE versions prior to 12.6, prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1 a medium severity vulnerability CVE-2024-8237 was detected. This vulnerability allows attackers to crash the system using a fake cargo.toml file. To fix this issue, users are advised to upgrade GitLab CE/EE to versions 17.6.1, 17.5.3, or 17.4.5. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-8237.
In GitLab EE versions starting from 17.3 before 17.3.7, starting from 17.4 before 17.4.4 and starting from 17.5 before 17.5.2 a medium severity vulnerability CVE-2024-10240 was detected. This vulnerability allows unauthenticated users to access details about merge requests (MR) in a private project under specific conditions. To fix this issue, users are advised to upgrade GitLab EE to versions 17.6.1, 17.5.3, or 17.4.5. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-10240.
Read more Developer ToolsIn Kubernetes versions prior to 1.28.11, and from 1.29.0 to 1.29.6 and 1.30.0 to 1.30.2 a high severity vulnerability CVE-2024-10220 was detected. This vulnerability allows attackers to execute arbitrary commands via specially crafted gitRepo volumes, potentially compromising the affected system. To fix this issue, users should upgrade Kubernetes to versions 1.28.12, 1.29.7, 1.30.3. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-10220.
Read more Developer ToolsIn Gogs versions 0.12.7 and prior a critical severity vulnerability CVE-2022-1884 was found. This vulnerability allows attackers to execute arbitrary commands on the server by uploading a malicious config file. It affects all Windows installations with repository uploads enabled, risking unauthorized access and system compromise. To fix this issue, users are advised to upgrade to version 0.12.8 or the latest 0.13.0+dev. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2022-1884.
Read more Developer ToolsIn Harbor versions before 2.5.2 a high severity vulnerability CVE-2022-31669 was detected. This vulnerability allows attackers to modify tag immutability policies in other projects by sending requests with an ID that belongs to a project the currently authenticated user doesn’t have access to. To fix this issue, users must upgrade to Harbor version 2.5.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-31669.
Read more Developer Tools