<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:49:38 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-00478</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-00478</link>
      <description>bdu:2025-00478</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-00478</guid>
    </item>
    <item>
      <title>BIT-gitlab-2024-8647 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2024-8647</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2024-8647</guid>
    </item>
    <item>
      <title>certfr-2024-avi-1065 — De multiples vulnérabilités ont été découvertes dans les produits GitLab. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1065</link>
      <description>certfr-2024-avi-1065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-1065</guid>
    </item>
    <item>
      <title>EUVD-2026-206978</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-206978</link>
      <description>EUVD-2026-206978</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-206978</guid>
    </item>
    <item>
      <title>fkie_cve-2024-8647</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-8647</link>
      <description>&lt;p&gt;An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-8647</guid>
    </item>
    <item>
      <title>GHSA-4xpw-245v-vp2w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4xpw-245v-vp2w</link>
      <description>&lt;p&gt;An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4xpw-245v-vp2w</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-8647</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-8647</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gitlab&lt;/p&gt;
&lt;p&gt;An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gitlab&lt;/p&gt;
&lt;p&gt;An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-8647</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3683 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3683</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Informationen offenzulegen, einen Denial of Service zu verursachen, einen Cross-Site Scripting Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen und potentiell andere Accounts zu übernehmen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Informationen offenzulegen, einen Denial of Service zu verursachen, einen Cross-Site Scripting Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen und potentiell andere Accounts zu übernehmen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3683</guid>
    </item>
  </channel>
</rss>
