GitLab Multiple Vulnerabilities
Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, remote code execution, cross-site scripting, denial of service condition and security restriction bypass on the targeted system.
Note:
CVE-2026-85706 is being exploited in the wild. Under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. Hence, the risk level is rated as Medium risk.
Impact
- Information Disclosure
- Security Restriction Bypass
- Remote Code Execution
- Cross-Site Scripting
- Denial of Service
System / Technologies affected
- GitLab Community Edition (CE) versions prior to 19.3.2, 19.2.6, 19.1.8
- GitLab Enterprise Edition (EE) versions prior to 19.3.2, 19.2.6, 19.1.8
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2024-11222
- CVE-2025-14871
- CVE-2026-1168
- CVE-2026-3855
- CVE-2026-7514
- CVE-2026-8030
- CVE-2026-12910
- CVE-2026-13210
- CVE-2026-16794
- CVE-2026-19619
- CVE-2026-78252
- CVE-2026-79708
- CVE-2026-82837
- CVE-2026-85706
- CVE-2026-86340
- CVE-2026-86341
- CVE-2026-87719
- CVE-2026-88765
沒有留言:
發佈留言