Репост из: Технологический Болт Генона
Наша постоянная, но подзабытая рубрика
Обновляем гитлабчики 💅💅💅
GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
Приятно видеть как bug bounty реально работает у GitLab. Critical и High это прям хорошо.
Обновляем гитлабчики 💅💅💅
CVE-2026-19478 - Code Injection issue via GraphQL directive impacts GitLab CE/EE
GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Impacted Versions: GitLab CE/EE: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4
CVSS 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H)
Thanks hiimguardian for reporting this vulnerability through our HackerOne bug bounty program.
CVE-2026-19650 - Cross-Site Request Forgery issue in GraphQL multiplex query handler impacts GitLab CE/EE
GitLab has remediated an issue that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.
Impacted Versions: GitLab CE/EE: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4
CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L)
Thanks kreep for reporting this vulnerability through our HackerOne bug bounty program.
GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
Приятно видеть как bug bounty реально работает у GitLab. Critical и High это прям хорошо.