GitLab 已修复 GitLab CE/EE 中的一个安全问题。该问题影响以下版本: 10.1.0 至 19.1.8 之前的所有版本 19.2 至 19.2.6 之前的版本 19.3 至 19.3.2 之前的版本 在特定条件下,由于内部数据输出端点的授权检查不当,经过身份验证的用户可能绕过预期的代理机制,从而访问敏感的凭据和令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88765 | 8.5 HIGH | Improper Neutralization of Special Elements used in a Command ('Command Injection') in Git |
| CVE-2026-13210 | 7.7 HIGH | Incorrect Authorization in GitLab |
| CVE-2026-12910 | 5.4 MEDIUM | Missing Authentication for Critical Function in GitLab |
No comments yet