- Sep 04, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
Robert Speicher authored
Prepare 13.1.11-ee release See merge request gitlab-org/gitlab!41343
- Sep 03, 2020
-
- Sep 02, 2020
-
-
Robert Speicher authored
Update docs in 13-1-stable-ee to support updated lint test See merge request gitlab-org/gitlab!41129
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
Mayra Cabrera authored
Protect OAuth endpoints from brute force/password stuffing See merge request gitlab-org/security/gitlab!792
-
Marcel Amirault authored
Signed-off-by:
Rémy Coutable <remy@rymai.me>
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Sep 01, 2020
-
-
Robert Speicher authored
Security check validity of repository mirror urls See merge request gitlab-org/security/gitlab!833
-
GitLab Release Tools Bot authored
Add scopes presence validation on OAuth Application creation See merge request gitlab-org/security/gitlab!907
-
Kerri Miller authored
-
Stan Hu authored
Previously if the import URL contained passwords that may look like hostnames or ports when unescaped, `Addressable::URI` would fail to parse. Since we really don't care about the username/password component, remove them from Gitlab::UrlSanitizer and then check the resulting value.
-
Kerri Miller authored
For security reasons, we need to check the validity of remote URLs to avoid users specifying blocked URLs (such as localhost)
-
- Update OAuth Applications controllers to disallow empty scopes application creation
-
GitLab Release Tools Bot authored
2FA requirement bypass using the API See merge request gitlab-org/security/gitlab!876
-
Change the way of treating nil current user Add specs to new class Add changelog entry Add specs for new auth method Rename Verificator to verifier Rename method in verifier Add cr remarks Add cr remarks
-
GitLab Release Tools Bot authored
Set maximum limit for profile events See merge request gitlab-org/security/gitlab!879
-
GitLab Release Tools Bot authored
GitLab Runner version upgrade See merge request gitlab-org/security/gitlab!886
-
GitLab Release Tools Bot authored
Malicious user can block gitlab.com users by exploiting 2FA inheritance logic See merge request gitlab-org/security/gitlab!801
-
GitLab Release Tools Bot authored
Previously created sessions remain active after activating 2FA See merge request gitlab-org/security/gitlab!865
-
GitLab Release Tools Bot authored
Delete members invites created by users being deleted See merge request gitlab-org/security/gitlab!830
-
GitLab Release Tools Bot authored
Pre-generation & Static 2FA Authenticator Secret Code can cause risks to accounts See merge request gitlab-org/security/gitlab!808
-
GitLab Release Tools Bot authored
Disabled Repository functionality - Still Able To Access The Project Files and Container Registry via Deploy Token See merge request gitlab-org/security/gitlab!889
-
GitLab Release Tools Bot authored
Improper Access Control on Deploy-Key See merge request gitlab-org/security/gitlab!892
-
GitLab Release Tools Bot authored
Validate Snippet global id in GraphQL destroy mutation See merge request gitlab-org/security/gitlab!730
-
GitLab Release Tools Bot authored
Merge branch 'security-220-dblessing-revoke-remember-me-on-session-revocation-13-1' into '13-1-stable-ee' Invalidate remember me when an active session is revoked See merge request gitlab-org/security/gitlab!855
-
GitLab Release Tools Bot authored
Rate limit on webhooks testing feature See merge request gitlab-org/security/gitlab!827
-