GitLab 已修复 GitLab CE/EE 中的一个问题,该问题影响从 15.7 起至 19.1.8 之前、19.2 起至 19.2.6 之前、以及 19.3 起至 19.3.2 之前的所有版本。在特定条件下,由于环境作用域模式匹配器中的输入验证不当,已认证用户可能能够访问超出其预期环境作用域范围的 CI/CD 变量。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88765 | 8.5 HIGH | Improper Neutralization of Special Elements used in a Command ('Command Injection') in Git |
| CVE-2026-12910 | 5.4 MEDIUM | Missing Authentication for Critical Function in GitLab |
| CVE-2026-82837 | 5.3 MEDIUM | Insertion of Sensitive Information Into Sent Data in GitLab |
No comments yet