GitLab 已修复 GitLab EE 中的一个漏洞。该漏洞影响 12.3 至 19.1.8、19.2 中 19.2.6 之前的版本以及 19.3 中 19.3.2 之前的版本。在特定条件下,该漏洞可能允许经过身份验证的用户通过导入一个精心构造的 Git 项目归档文件,使高级搜索索引所使用的 Unicode 转换缓冲区发生溢出,从而实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13210 | 7.7 HIGH | Incorrect Authorization in GitLab |
| CVE-2026-12910 | 5.4 MEDIUM | Missing Authentication for Critical Function in GitLab |
| CVE-2026-82837 | 5.3 MEDIUM | Insertion of Sensitive Information Into Sent Data in GitLab |
No comments yet