GitLab 已修复 GitLab CE/EE 中存在的一个安全问题,该问题影响所有 19.2.7 之前的 19.1 版本、19.3.3 之前的 19.3 版本以及 19.4.1 之前的 19.4 版本。在某些条件下,该漏洞可能允许已认证用户伪造合并请求的作者身份,并将内容归因于目标实例上任意现有用户。此问题是由于在直接传输导入过程中对临时缓存状态的不当依赖所导致。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89078 | 9.9 CRITICAL | Double Free in GitLab |
| CVE-2026-93577 | 9.9 CRITICAL | Integer Overflow or Wraparound in GitLab |
| CVE-2026-92470 | 7.7 HIGH | Missing Authorization in GitLab |
| CVE-2026-92874 | 5.4 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92529 | 4.3 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92628 | 3.1 LOW | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
No comments yet