Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rodrigo Tomonari

Researcher fromGitLab
#22143of 53,634
10.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2023-29945
5.0
2023-09-11
Gitlab · Gitlab · CVE-2023-4630
**Name of the Vulnerable Software and Affected Versions** GitLab versions 10.6 through 16.1.5 GitLab versions 16.2 through 16.2.5 GitLab versions 16.3 through 16.3.1 **Description** An issue has been discovered in GitLab where any user can read limited information about any project's imports. **Recommendations** For GitLab versions 10.6 through 16.1.5, update to version 16.1.5 or later. For GitLab versions 16.2 through 16.2.5, update to version 16.2.5 or later. For GitLab versions 16.3 through 16.3.1, update to version 16.3.1 or later.
PT-2023-24406
5.3
2023-07-13
Gitlab · Gitlab Ce/Ee · CVE-2023-3362
**Name of the Vulnerable Software and Affected Versions** GitLab CE/EE versions 16.0 through 16.0.5 GitLab CE/EE version 16.1.0 **Description** An information disclosure issue in GitLab CE/EE allows unauthenticated actors to access the import error information if a project was imported from GitHub. **Recommendations** For GitLab CE/EE versions 16.0 through 16.0.5, update to version 16.0.6 or later. For GitLab CE/EE version 16.1.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to project import error information until a patch is available.