GitLab 修复了 GitLab EE 中的一个安全问题,该问题影响所有 19.1(不含 19.2.7)之前、19.3(不含 19.3.3)之前,以及 19.4(不含 19.4.1)之前的版本。在某些情况下,拥有开发者角色权限的已认证用户可能绕过管理员配置的 AI 工具治理控制措施,用于其无权管理的命名空间(namespace)中的工作流,原因是授权检查存在缺陷。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89078 | 9.9 CRITICAL | Double Free in GitLab |
| CVE-2026-93577 | 9.9 CRITICAL | Integer Overflow or Wraparound in GitLab |
| CVE-2026-92470 | 7.7 HIGH | Missing Authorization in GitLab |
| CVE-2026-92874 | 5.4 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92530 | 4.3 MEDIUM | Use of Less Trusted Source in GitLab |
| CVE-2026-92628 | 3.1 LOW | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
No comments yet