<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:05:10 +0000</lastBuildDate>
    <item>
      <title>BIT-gitlab-2023-3964 — Incorrect Authorization in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2023-3964</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2023-3964</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0991 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;GitLab&lt;/span&gt;. Certaines d'entre elles permet…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0991</link>
      <description>certfr-2023-avi-0991</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0991</guid>
    </item>
    <item>
      <title>EUVD-2026-308652</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308652</link>
      <description>EUVD-2026-308652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308652</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3964</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3964</link>
      <description>&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3964</guid>
    </item>
    <item>
      <title>GHSA-7m6x-h8vx-f72m</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7m6x-h8vx-f72m</link>
      <description>&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7m6x-h8vx-f72m</guid>
    </item>
    <item>
      <title>gsd-2023-3964</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3964</link>
      <description>gsd-2023-3964</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3964</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3041 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3041</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, seine Berechtigungen zu erweitern oder XSS-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, seine Berechtigungen zu erweitern oder XSS-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3041</guid>
    </item>
  </channel>
</rss>
