FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-25 11:22:49 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
8ba8278d-db06-11eb-ba49-001b217b3468Gitlab -- Multiple Vulnerabilities

Gitlab reports:

DoS using Webhook connections

CSRF on GraphQL API allows executing mutations through GET requests

Private projects information disclosure

Denial of service of user profile page

Single sign-on users not getting blocked

Some users can push to Protected Branch with Deploy keys

A deactivated user can access data through GraphQL

Reflected XSS in release edit page

Clipboard DOM-based XSS

Stored XSS on Audit Log

Forks of public projects by project members could leak codebase

Improper text rendering

HTML Injection in full name field


Discovery 2021-07-01
Entry 2021-07-02
gitlab-ce
ge 14.0.0 lt 14.0.2

ge 13.12.0 lt 13.12.6

ge 8.0.0 lt 13.11.6

https://about.gitlab.com/releases/2021/07/01/security-release-gitlab-14-0-2-released/