<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:56:12 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-06159</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06159</link>
      <description>bdu:2024-06159</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06159</guid>
    </item>
    <item>
      <title>BIT-gitlab-2024-3035 — Authorization Bypass Through User-Controlled Key in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2024-3035</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2024-3035</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0659 — De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0659</link>
      <description>certfr-2024-avi-0659</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0659</guid>
    </item>
    <item>
      <title>EUVD-2026-186056</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-186056</link>
      <description>EUVD-2026-186056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-186056</guid>
    </item>
    <item>
      <title>fkie_cve-2024-3035</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-3035</link>
      <description>&lt;p&gt;A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-3035</guid>
    </item>
    <item>
      <title>GHSA-rvj3-54w6-vrw6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rvj3-54w6-vrw6</link>
      <description>&lt;p&gt;A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rvj3-54w6-vrw6</guid>
    </item>
    <item>
      <title>gsd-2024-3035</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-3035</link>
      <description>gsd-2024-3035</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-3035</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-3035</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3035</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gitlab&lt;/p&gt;
&lt;p&gt;A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gitlab&lt;/p&gt;
&lt;p&gt;A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3035</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1787 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1787</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um seine Privilegien zu erweitern, einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um seine Privilegien zu erweitern, einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1787</guid>
    </item>
  </channel>
</rss>
