Gitlab reports:
Injection of Network Error Logging (NEL) headers in kubernetes proxy response could lead to ATO abusing OAuth flows
Denial of Service by repeatedly sending unauthenticated requests for diff-files
CI_JOB_TOKEN could be used to obtain GitLab session
Open redirect in releases API
Client-Side Path Traversal in Harbor artifact links
HTML injection in vulnerability details could lead to Cross Site Scripting
Leak branch names of projects with confidential repository
Non member can view unresolved threads marked as internal notes
Uncontrolled Resource Consumption through a maliciously crafted file
Certain sensitive information passed as literals inside GraphQL mutations retained in GraphQL logs
Information disclosure of confidential incidents details to a group member in Gitlab Wiki
Domain Confusion in GitLab Pages Unique Domain Implementation
This Cyber News was published on www.tenable.com. Publication date: Fri, 13 Dec 2024 14:56:01 +0000