- Jul 07, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Jul 06, 2021
-
-
Mayra Cabrera authored
Disable filesystem and network premailer strategies See merge request gitlab-org/security/gitlab!1546
-
- Jul 05, 2021
-
-
Heinrich Lee Yu authored
Changelog: security
-
- Jul 01, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Mayra Cabrera authored
Prevent GraphQL API access by deactivated users See merge request gitlab-org/security/gitlab!1527
-
- Jun 30, 2021
-
-
Amy Phillips authored
Bump rails gem version to 6.0.3.7 See merge request gitlab-org/security/gitlab!1516
-
Amy Phillips authored
Limit creation of issues based on issue type See merge request gitlab-org/security/gitlab!1481
-
GitLab Release Tools Bot authored
Copy feature visibility settings to a fork See merge request gitlab-org/security/gitlab!1524
-
GitLab Release Tools Bot authored
Update rdoc to 6.3.1 See merge request gitlab-org/security/gitlab!1535
-
GitLab Release Tools Bot authored
Add new username validation See merge request gitlab-org/security/gitlab!1497
-
GitLab Release Tools Bot authored
Avoid disclosing project in web IDE See merge request gitlab-org/security/gitlab!1513
-
GitLab Release Tools Bot authored
Clipboard DOM-based XSS in Markdown [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1452
-
GitLab Release Tools Bot authored
Add sanitizing for name field See merge request gitlab-org/security/gitlab!1491
-
GitLab Release Tools Bot authored
Fix XSS in release Edits See merge request gitlab-org/security/gitlab!1485
-
GitLab Release Tools Bot authored
Fix XSS on audit log for feature flag actions See merge request gitlab-org/security/gitlab!1475
-
GitLab Release Tools Bot authored
Update Nokogiri to 1.11.4 See merge request gitlab-org/security/gitlab!1480
-
GitLab Release Tools Bot authored
Add omniauth_user check when verifying user cap See merge request gitlab-org/security/gitlab!1503
-
GitLab Release Tools Bot authored
Add total http read timeout See merge request gitlab-org/security/gitlab!1393
-
GitLab Release Tools Bot authored
Some users can push to Protected Branch with Deploy keys See merge request gitlab-org/security/gitlab!1477
-
GitLab Release Tools Bot authored
Fix merge request diff display issue with unsupported encoding See merge request gitlab-org/security/gitlab!1425
-
It contains multiple security fixes. One of them prevents string polymorphic route arguments and causes some additional changes to be made along with just bumping gem version Changelog: security
-
- Jun 28, 2021
-
-
Alishan Ladhani authored
Created a fork because rdoc 6.3.1 is missing a file. Changelog: security
-
- Jun 24, 2021
-
-
Alexis Kalderimis authored
This ensures that deactivated users (and other users who fail the `api_access` check, such as blocked users, or users who haven't accepted terms of service) get a forbidden response from the GraphQL API endpoint. Changelog: security
-
- Jun 23, 2021
-
-
mksionek authored
Changelog: security
-
Igor Drozdov authored
When a public project with a private feature is forked, it's expected that the fork will also have the feature private For example, forking a public project with private repo might accidently lead to a repository code exposure Changelog: security
-
- Jun 22, 2021
-
-
Etienne Baqué authored
Checking user identities presence in that check. Also added related rspecs. Changelog: added EE: true
-
Francisco Javier López authored
In this commit we avoid disclosing project info through the web IDE by checking if the user can read the project. Changelog: security
-
- Jun 16, 2021
- Jun 10, 2021
-
-
Sarah Yasonik authored
Ensure test case and requirement issues are only creatable on EE with requisite permissions. Changelog: security
-
- Jun 09, 2021
-
-
Alishan Ladhani authored
Changelog: security
-
Shinya Maeda authored
This commit fixes the vulnerability that deploy key access check for protected branch wrongly falls back to role-based permission check to authorize the user to have Maintainer access. Changelog: security
-
- Jun 08, 2021
-
-
Tan Le authored
An adversary can craft a malicious link in the feature flag description. This action creates an audit event which is then presented to an administrator. Clicking on the link will grant admin role to the adversary. This change ensures that: - HTML tags are removed before rendering the audit log actions - HTML tags are removed in feature flag related audit event messages - HTML tags are removed when saving `custom_message` in audit events Changelog: security
-
- Jun 01, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
-