Gitlab -- Multiple Vulnerabilities

Affected packages
15.9.0 <= gitlab-ce < 15.9.2
15.8.0 <= gitlab-ce < 15.8.4
9.0.0 <= gitlab-ce < 15.7.8


VuXML ID f7c5b3a9-b9fb-11ed-99c6-001b217b3468
Discovery 2023-03-02
Entry 2023-03-03

Gitlab reports:

Stored XSS via Kroki diagram

Prometheus integration Google IAP details are not hidden, may leak account details from instance/group/project settings

Improper validation of SSO and SCIM tokens while managing groups

Maintainer can leak Datadog API key by changing Datadog site

Clipboard based XSS in the title field of work items

Improper user right checks for personal snippets

Release Description visible in public projects despite release set as project members only

Group integration settings sensitive information exposed to project maintainers

Improve pagination limits for commits

Gitlab Open Redirect Vulnerability

Maintainer may become an Owner of a project


CVE Name CVE-2022-3381
CVE Name CVE-2022-3758
CVE Name CVE-2022-4007
CVE Name CVE-2022-4289
CVE Name CVE-2022-4331
CVE Name CVE-2022-4462
CVE Name CVE-2023-0050
CVE Name CVE-2023-0223
CVE Name CVE-2023-0483
CVE Name CVE-2023-1072
CVE Name CVE-2023-1084