GitLab 已修复 GitLab CE/EE 中一个影响以下版本的漏洞:15.11 之前的所有版本、19.2.7 之前的 19.3 版本以及 19.4.1 之前的 19.4 版本。在特定条件下,由于 GraphQL API 中的授权机制执行不当,未经身份验证的用户可能能够读取包含敏感变量值的 CI/CD 作业日志(trace)内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84739 | 8.7 HIGH | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Gi |
| CVE-2026-8937 | 4.3 MEDIUM | Missing Authorization in GitLab |
| CVE-2026-10518 | 4.3 MEDIUM | Incorrect Authorization in GitLab |
No comments yet