GitLab 已修复 GitLab CE/EE 中的一个安全问题,该问题影响以下版本:19.0 至 19.2.6(不含 19.2.7)、19.3 至 19.3.2(不含 19.3.3)以及 19.4 至 19.4.0(不含 19.4.1)。由于可见 Epic(史诗)中关联的工作项(work items)缺少必要的授权检查,在特定条件下,已认证用户可能能够读取其无权访问的项目中的私有子 Issue(子问题)内容,包括标题和描述。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84739 | 8.7 HIGH | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Gi |
| CVE-2026-10518 | 4.3 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-4523 | 3.7 LOW | Missing Authorization in GitLab |
No comments yet