Author: Angelo Barbosa

CVE-2023-4912 | GitLab Enterprise Edition prior 16.4.3/16.5.3/16.6.1 Mermaid Diagram resource consumption

A vulnerability was found in GitLab Enterprise Edition. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Mermaid Diagram Handler. The manipulation leads to resource consumption. This vulnerability is handled as CVE-2023-4912. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-4658 | GitLab Enterprise Edition prior 16.4.3/16.5.3/16.6.1 Allowed to Merge access control

A vulnerability was found in GitLab Enterprise Edition. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Allowed to Merge Handler. The manipulation leads to improper access controls. This vulnerability is known as CVE-2023-4658. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-4317 | GitLab prior 16.4.3/16.5.3/16.6.1 Pipeline Schedule access control

A vulnerability was found in GitLab. It has been classified as critical. Affected is an unknown function of the component Pipeline Schedule Handler. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2023-4317. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-3949 | GitLab prior 16.4.3/16.5.3/16.6.1 Public Project information disclosure

A vulnerability was found in GitLab and classified as problematic. This issue affects some unknown processing of the component Public Project Handler. The manipulation leads to information disclosure. The identification of this vulnerability is CVE-2023-3949. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More