2026年9月14日星期一

GitLab Multiple Vulnerabilities

GitLab Multiple Vulnerabilities

Release Date: 14 Sep 2026

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, remote code execution, cross-site scripting, denial of service condition and security restriction bypass on the targeted system.

 

Note: 

CVE-2026-85706 is being exploited in the wild. Under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. Hence, the risk level is rated as Medium risk.


Impact

  • Information Disclosure
  • Security Restriction Bypass
  • Remote Code Execution
  • Cross-Site Scripting
  • Denial of Service

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 19.3.2, 19.2.6, 19.1.8
  • GitLab Enterprise Edition (EE) versions prior to 19.3.2, 19.2.6, 19.1.8

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

GitLab 多個漏洞

GitLab 多個漏洞 發佈日期: 2026年09月14日 於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、遠端執行程式碼、跨網站指令碼、阻斷服務狀況及繞過保安限制。   注意: CVE-2026-85706 正在被廣泛利用。在某些情況下,由...