Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-5106: Merge branch 'jy-import-runner-security' into 'master' (67039cfc) · Commits · GitLab.org / GitLab · GitLab

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

CVE
#git#auth

Skip to content

GitLab

Next

    • Why GitLab
    • Pricing
    • Contact Sales
    • Explore
  • Why GitLab

  • Pricing

  • Contact Sales

  • Explore

  • Sign in

  • Get free trial

  • GitLab.org

  • GitLab

  • Commits

  • 67039cfc

Commit 67039cfc authored Sep 21, 2023 by Mayra Cabrera 💡

Browse files

Merge branch ‘jy-import-runner-security’ into ‘master’

Mark any CI builds that are not complete as canceled when imported

See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3592

Merged-by: Mayra Cabrera <[email protected]> Approved-by: Fabio Pitino <[email protected]> Approved-by: Dominic Couture <[email protected]> Reviewed-by: Fabio Pitino <[email protected]> Co-authored-by: Jessie Young <[email protected]>

parents eea873dc ac0f8d8e

  • Changes 7

Expand all Hide whitespace changes

Inline Side-by-side

0% or .

You are about to add 0 people to the discussion. Proceed with caution.

Finish editing this message first!

Please register or sign in to comment

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda