<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:11:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-11288</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-11288</link>
      <description>bdu:2024-11288</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-11288</guid>
    </item>
    <item>
      <title>BIT-gitlab-2024-11274 — URL Redirection to Untrusted Site ('Open Redirect') in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2024-11274</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2024-11274</guid>
    </item>
    <item>
      <title>certfr-2024-avi-1065 — De multiples vulnérabilités ont été découvertes dans les produits GitLab. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1065</link>
      <description>certfr-2024-avi-1065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-1065</guid>
    </item>
    <item>
      <title>EUVD-2026-206981</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-206981</link>
      <description>EUVD-2026-206981</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-206981</guid>
    </item>
    <item>
      <title>fkie_cve-2024-11274</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-11274</link>
      <description>&lt;p&gt;An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-11274</guid>
    </item>
    <item>
      <title>GHSA-fr8h-r296-xggf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fr8h-r296-xggf</link>
      <description>&lt;p&gt;An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fr8h-r296-xggf</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-11274</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-11274</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gitlab&lt;/p&gt;
&lt;p&gt;An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gitlab&lt;/p&gt;
&lt;p&gt;An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-11274</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3683 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3683</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Informationen offenzulegen, einen Denial of Service zu verursachen, einen Cross-Site Scripting Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen und potentiell andere Accounts zu übernehmen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Informationen offenzulegen, einen Denial of Service zu verursachen, einen Cross-Site Scripting Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen und potentiell andere Accounts zu übernehmen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3683</guid>
    </item>
  </channel>
</rss>
