<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:17:50 +0000</lastBuildDate>
    <item>
      <title>BIT-gitlab-2023-1965</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2023-1965</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn&amp;#39;t enabled by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn&amp;#39;t enabled by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2023-1965</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0351 — De multiples vulnérabilités ont été découvertes dans GitLab. Certaines
d'entre elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0351</link>
      <description>certfr-2023-avi-0351</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0351</guid>
    </item>
    <item>
      <title>EUVD-2026-212698</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-212698</link>
      <description>EUVD-2026-212698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-212698</guid>
    </item>
    <item>
      <title>fkie_cve-2023-1965</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1965</link>
      <description>&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn&amp;#39;t enabled by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn&amp;#39;t enabled by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-1965</guid>
    </item>
    <item>
      <title>GHSA-cxfp-vwqp-ghxf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cxfp-vwqp-ghxf</link>
      <description>&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn&amp;#39;t enabled by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn&amp;#39;t enabled by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cxfp-vwqp-ghxf</guid>
    </item>
    <item>
      <title>gsd-2023-1965</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-1965</link>
      <description>gsd-2023-1965</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-1965</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1130 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1130</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um seine Privilegien zu erweitern, Sicherheitsvorkehrungen zu umgehen, einen Cross Site Scripting Angriff durchzuführen und Informationen offenzulegen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um seine Privilegien zu erweitern, Sicherheitsvorkehrungen zu umgehen, einen Cross Site Scripting Angriff durchzuführen und Informationen offenzulegen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1130</guid>
    </item>
  </channel>
</rss>
