5.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
- @LeSuisse accepted
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @krav
- @yayayayaka
- @LeSuisse published on GitHub
Server-Side Request Forgery (SSRF) in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import, due to insufficient validation of secondary URLs.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
-
@yayayayaka Yaya <github@uwu.is>
7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
40 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- gitlab-ee
- perl5Packages.AlienBuildPluginDownloadGitLab
- perlPackages.AlienBuildPluginDownloadGitLab
- @LeSuisse restored package gitlab-ee
- @LeSuisse accepted
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @leona-ya
- @yayayayaka
- @krav
- @talyz
- @gabyx
- @LeSuisse published on GitHub
Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@leona-ya Leona Maroni <nix@leona.is>
-
@yayayayaka Yaya <github@uwu.is>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
- @LeSuisse accepted
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @krav
- @yayayayaka
- @LeSuisse published on GitHub
Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
-
@yayayayaka Yaya <github@uwu.is>
3.7 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @yayayayaka
- @krav
- @LeSuisse accepted
- @LeSuisse published on GitHub
Authorization Bypass Through User-Controlled Key in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@yayayayaka Yaya <github@uwu.is>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
5.4 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @yayayayaka
- @talyz
- @krav
- @LeSuisse accepted
- @LeSuisse published on GitHub
Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@yayayayaka Yaya <github@uwu.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
3.1 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @yayayayaka
- @krav
- @LeSuisse accepted
- @LeSuisse published on GitHub
Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@yayayayaka Yaya <github@uwu.is>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
4.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @yayayayaka
- @krav
- @LeSuisse accepted
- @LeSuisse published on GitHub
Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@yayayayaka Yaya <github@uwu.is>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
7.3 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): High (H)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @yayayayaka
- @talyz
- @krav
- @LeSuisse accepted
- @LeSuisse published on GitHub
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@yayayayaka Yaya <github@uwu.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
8.7 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
- @LeSuisse accepted
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @yayayayaka
- @krav
- @LeSuisse published on GitHub
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@yayayayaka Yaya <github@uwu.is>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
2.6 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
40 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- gitlab-ee
- perl5Packages.AlienBuildPluginDownloadGitLab
- perlPackages.AlienBuildPluginDownloadGitLab
- @LeSuisse restored package gitlab-ee
- @LeSuisse accepted
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @krav
- @yayayayaka
- @LeSuisse published on GitHub
Improper Neutralization of Substitution Characters in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply due to improper neutralization in email template processing.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
-
@yayayayaka Yaya <github@uwu.is>
4.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): Low (L)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- perl5Packages.AlienBuildPluginDownloadGitLab
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @yayayayaka
- @krav
- @LeSuisse accepted
- @LeSuisse published on GitHub
Improper Restriction of Rendered UI Layers or Frames in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@yayayayaka Yaya <github@uwu.is>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
8.7 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
39 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
-
@LeSuisse
ignored
maintainer.ignore
5 maintainers
- @gabyx
- @leona-ya
- @talyz
- @yayayayaka
- @krav
- @LeSuisse accepted
- @LeSuisse published on GitHub
Authorization Bypass Through User-Controlled Key in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality.
References
Affected products
- <18.10.8
- <18.11.5
- <19.0.2
Matching in nixpkgs
pkgs.gitlab
GitLab Community Edition
Ignored packages (39)
pkgs.gitlab-art
Pull cross-project Gitlab artifact dependencies
pkgs.gitlab-duo
CLI for GitLab AI assistant
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.gitlab-ci-ls
GitLab CI Language Server (gitlab-ci-ls)
pkgs.gitlab-pages
Daemon used to serve static websites for GitLab users
pkgs.gitlab-shell
SSH access and repository management app for GitLab
pkgs.danger-gitlab
Gem that exists to ensure all dependencies are set up for Danger with GitLab
pkgs.gitlab-clippy
Convert clippy warnings into GitLab Code Quality report
pkgs.gitlab-runner
GitLab Runner the continuous integration executor of GitLab
pkgs.gitlab-triage
GitLab's issues and merge requests triage, automated
pkgs.gitlab-ci-local
Run gitlab pipelines locally as shell executor or docker executor
pkgs.gitlab-timelogs
CLI utility to support you with your time logs in GitLab
pkgs.gitlab-ci-linter
.gitlab-ci.yml lint helper tool
pkgs.gitlab-workhorse
None
pkgs.gitlab-release-cli
Toolset to create, retrieve and update releases on GitLab
pkgs.ocamlPackages.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-container-registry
GitLab Docker toolset to pack, ship, store, and deliver content
pkgs.ocamlPackages.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages.gitlab-unix
Gitlab APIv4 Unix library
pkgs.rubyPackages.gitlab-markup
None
pkgs.terraform-providers.gitlab
None
pkgs.ocamlPackages_latest.gitlab
Native OCaml bindings to Gitlab REST API v4
pkgs.gitlab-elasticsearch-indexer
Indexes Git repositories into Elasticsearch for GitLab
pkgs.haskellPackages.gitlab-haskell
A Haskell library for the GitLab web API
pkgs.rubyPackages_3_3.gitlab-markup
None
pkgs.rubyPackages_3_4.gitlab-markup
None
pkgs.rubyPackages_4_0.gitlab-markup
None
pkgs.python313Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python313Packages.python-gitlab
Interact with GitLab API
pkgs.python314Packages.mkdocs-gitlab
MkDocs plugin to transform strings into links to a Gitlab repository
pkgs.python314Packages.python-gitlab
Interact with GitLab API
pkgs.ocamlPackages_latest.gitlab-jsoo
Gitlab APIv4 JavaScript library
pkgs.ocamlPackages_latest.gitlab-unix
Gitlab APIv4 Unix library
pkgs.terraform-providers.gitlabhq_gitlab
None
pkgs.gnomeExtensions.gitlab-time-tracking
Track time spent on GitLab issues with a convenient system tray timer.
pkgs.prometheus-gitlab-ci-pipelines-exporter
Prometheus / OpenMetrics exporter for GitLab CI pipelines insights
pkgs.vscode-extensions.gitlab.gitlab-workflow
GitLab extension for Visual Studio Code
pkgs.perlPackages.AlienBuildPluginDownloadGitLab
Alien::Build plugin to download from GitLab
Package maintainers
Ignored maintainers (5)
-
@gabyx Gabriel Nützi <gnuetzi@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@yayayayaka Yaya <github@uwu.is>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>