- Sep 02, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
Mayra Cabrera authored
Protect OAuth endpoints from brute force/password stuffing See merge request gitlab-org/security/gitlab!843
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
- Sep 01, 2020
-
-
Robert Speicher authored
Security check validity of repository mirror urls See merge request gitlab-org/security/gitlab!860
-
GitLab Release Tools Bot authored
Add scopes presence validation on OAuth Application creation See merge request gitlab-org/security/gitlab!905
-
Kerri Miller authored
-
- Update OAuth Applications controllers to disallow empty scopes application creation
-
GitLab Release Tools Bot authored
2FA requirement bypass using the API See merge request gitlab-org/security/gitlab!874
-
GitLab Release Tools Bot authored
Set maximum limit for profile events See merge request gitlab-org/security/gitlab!877
-
GitLab Release Tools Bot authored
GitLab Runner version upgrade See merge request gitlab-org/security/gitlab!884
-
GitLab Release Tools Bot authored
Malicious user can block gitlab.com users by exploiting 2FA inheritance logic See merge request gitlab-org/security/gitlab!856
-
GitLab Release Tools Bot authored
Previously created sessions remain active after activating 2FA See merge request gitlab-org/security/gitlab!858
-
GitLab Release Tools Bot authored
Delete members invites created by users being deleted See merge request gitlab-org/security/gitlab!859
-
GitLab Release Tools Bot authored
Pre-generation & Static 2FA Authenticator Secret Code can cause risks to accounts See merge request gitlab-org/security/gitlab!857
-
GitLab Release Tools Bot authored
Disabled Repository functionality - Still Able To Access The Project Files and Container Registry via Deploy Token See merge request gitlab-org/security/gitlab!887
-
GitLab Release Tools Bot authored
Improper Access Control on Deploy-Key See merge request gitlab-org/security/gitlab!890
-
GitLab Release Tools Bot authored
Validate Snippet global id in GraphQL destroy mutation See merge request gitlab-org/security/gitlab!839
-
GitLab Release Tools Bot authored
Merge branch 'security-220-dblessing-revoke-remember-me-on-session-revocation-13-3' into '13-3-stable-ee' Invalidate remember me when an active session is revoked See merge request gitlab-org/security/gitlab!853
-
GitLab Release Tools Bot authored
Rate limit on webhooks testing feature See merge request gitlab-org/security/gitlab!842
-
GitLab Release Tools Bot authored
Upgrade jQuery to v3.5 See merge request gitlab-org/security/gitlab!836
-
GitLab Release Tools Bot authored
Don't expose epic for users without permissions See merge request gitlab-org/security/gitlab!862
-
GitLab Release Tools Bot authored
Prevent OmniAuth from rendering arbitrary error messages See merge request gitlab-org/security/gitlab!847
-
GitLab Release Tools Bot authored
Invalidate two factor sign-in when user password changes See merge request gitlab-org/security/gitlab!844
-
GitLab Release Tools Bot authored
Prevent stale otp_user_id from signing-in incorrect user See merge request gitlab-org/security/gitlab!850
-
Stan Hu authored
Previously if the import URL contained passwords that may look like hostnames or ports when unescaped, `Addressable::URI` would fail to parse. Since we really don't care about the username/password component, remove them from Gitlab::UrlSanitizer and then check the resulting value.
-
- Aug 28, 2020
-
-
GitLab Release Tools Bot authored
Security websocket extensions update See merge request gitlab-org/security/gitlab!881
-
GitLab Release Tools Bot authored
Prevent project maintainers from editing group badges See merge request gitlab-org/security/gitlab!868
-
GitLab Release Tools Bot authored
Change conan api to use proper workhorse validation See merge request gitlab-org/security/gitlab!861
-
GitLab Release Tools Bot authored
Allow tokens only from running jobs for API auth See merge request gitlab-org/security/gitlab!866
-
Adds a finder class used for authentication with CI job tokens. It checks that the job's status is `running` and that the project is not removed.
-
GitLab Release Tools Bot authored
Sanitize vulnerability history comment See merge request gitlab-org/security/gitlab!825
-
GitLab Release Tools Bot authored
Persist EKS External ID before presenting it to the user See merge request gitlab-org/security/gitlab!841
-