GitLab 已修复了 GitLab CE/EE 中的一个问题,该问题影响以下版本:18.6 至 19.1.8 之前的所有版本、19.2 至 19.2.6 之前的版本,以及 19.3 至 19.3.2 之前的版本。在特定条件下,由于缺少对认证强制执行的检查,已认证的用户可能绕过 SAML SSO 登录限制,并在未使用 SSO 的情况下完成身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88765 | 8.5 HIGH | Improper Neutralization of Special Elements used in a Command ('Command Injection') in Git |
| CVE-2026-13210 | 7.7 HIGH | Incorrect Authorization in GitLab |
| CVE-2026-82837 | 5.3 MEDIUM | Insertion of Sensitive Information Into Sent Data in GitLab |
No comments yet