<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:41:15 +0000</lastBuildDate>
    <item>
      <title>BIT-gitlab-2023-3949 — Insertion of Sensitive Information Into Sent Data in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2023-3949</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects&amp;#39; release descriptions via an atom endpoint when release access on the public was set to only project members.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects&amp;#39; release descriptions via an atom endpoint when release access on the public was set to only project members.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2023-3949</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0991 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;GitLab&lt;/span&gt;. Certaines d'entre elles permet…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0991</link>
      <description>certfr-2023-avi-0991</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0991</guid>
    </item>
    <item>
      <title>EUVD-2026-261385</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261385</link>
      <description>EUVD-2026-261385</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261385</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3949</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3949</link>
      <description>&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects&amp;#39; release descriptions via an atom endpoint when release access on the public was set to only project members.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects&amp;#39; release descriptions via an atom endpoint when release access on the public was set to only project members.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3949</guid>
    </item>
    <item>
      <title>GHSA-c3hq-3p4c-ch2w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c3hq-3p4c-ch2w</link>
      <description>&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects&amp;#39; release descriptions via an atom endpoint when release access on the public was set to only project members.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects&amp;#39; release descriptions via an atom endpoint when release access on the public was set to only project members.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c3hq-3p4c-ch2w</guid>
    </item>
    <item>
      <title>gsd-2023-3949</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3949</link>
      <description>gsd-2023-3949</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3949</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3041 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3041</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, seine Berechtigungen zu erweitern oder XSS-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, seine Berechtigungen zu erweitern oder XSS-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3041</guid>
    </item>
  </channel>
</rss>
