- Dec 20, 2018
-
-
GitLab Release Tools Bot authored
[ci skip]
-
John Jarvis authored
- Dec 13, 2018
-
-
GitLab Release Tools Bot authored
[ci skip]
-
John Jarvis authored
[11.3] Validate LFS hrefs before downloading them See merge request gitlab/gitlabhq!2700
- Dec 06, 2018
-
-
GitLab Release Tools Bot authored
[ci skip]
- Dec 05, 2018
-
-
Cindy Pallares authored
[11.3] Prevent a path traversal attack on global file templates See merge request gitlab/gitlabhq!2671
-
- Nov 26, 2018
-
-
GitLab Release Tools Bot authored
[ci skip]
-
Steve Xuereb authored
[11.3] Reflected XSS in OAuth Authorize window due to redirect_uri allowing arbitrary protocols See merge request gitlab/gitlabhq!2581
-
Steve Xuereb authored
[11.3] Fix CRLF issue in UrlValidator See merge request gitlab/gitlabhq!2654
-
-
Steve Xuereb authored
[11.3] Redact sensitive information on workhorse log See merge request gitlab/gitlabhq!2586
-
Steve Xuereb authored
[11.3] Fix SSRF in project integrations See merge request gitlab/gitlabhq!2609
-
Steve Xuereb authored
[11.3] Resolve: "Provide email notification when a user changes their email address" See merge request gitlab/gitlabhq!2604
-
Steve Xuereb authored
[11.3] Fixed ability to comment on and edit/delete comments on locked or confidential issues See merge request gitlab/gitlabhq!2648
-
-
James Lopez authored
-
Steve Xuereb authored
[11.3] [pages] Possible symlink time of check to time of use race condition See merge request gitlab/gitlabhq!2651
-
Steve Xuereb authored
[11.3] Resolve "Personal access token with only `read_user` scope can be used to authenticate any web request" See merge request gitlab/gitlabhq!2657
- Nov 23, 2018
-
-
Steve Azzopardi authored
6.1.1 does not include the security fix, but 6.1.2 does.
-
Steve Xuereb authored
Merge branch 'security-11-3-xss-in-markdown-following-unrecognized-html-element' into 'security-11-3' [11.3] XSS in markdown following unrecognized HTML element See merge request gitlab/gitlabhq!2633
-
Steve Xuereb authored
[11.3] Fix XSS in mermaid diagrams See merge request gitlab/gitlabhq!2640
-
Steve Xuereb authored
[11.3] Don't expose confidential information in commit message list See merge request gitlab/gitlabhq!2644
-
Steve Xuereb authored
[11.3] Resolve: Promoting a milestone is missing an authorization check See merge request gitlab/gitlabhq!2621
-
Steve Xuereb authored
[11.3] Do not follow redirects in prometheus service See merge request gitlab/gitlabhq!2625
-
Steve Xuereb authored
[11.3] Stored XSS for Environments See merge request gitlab/gitlabhq!2616
-
Steve Azzopardi authored
-
Steve Xuereb authored
[11.3] Fixed read name of private groups See merge request gitlab/gitlabhq!2592
-
James Lopez authored
-
- Nov 21, 2018
-
-
Alessio Caiazza authored
-
- Nov 19, 2018
-
-
Bob Van Landuyt authored
This makes sure the user viewing the commit does not get to see anything they're not allowed to see
-
Winnie Hellmann authored
(cherry picked from commit f2e9f22f7d3d84abeea5ba2918ee5ffcc55f2dad) Conflicts: app/assets/javascripts/behaviors/markdown/render_mermaid.js
-
Winnie Hellmann authored
(cherry picked from commit fdea799d37ae9ca3f5e80f191a55be543a79857a)
-
- Nov 18, 2018
-
-
GitLab Release Tools Bot authored
[ci skip]
-
Steve Xuereb authored
[11.3] Prevent templated services from being imported See merge request gitlab/gitlabhq!2637
-
Steve Xuereb authored
[11.3] Escape user fullname while rendering autocomplete template to prevent XSS See merge request gitlab/gitlabhq!2608