vulnerability

FreeBSD: VID-3507bfb3-85d5-11ec-8c9c-001b217b3468 (CVE-2022-0344): Gitlab -- multiple vulnerabilities

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Feb 4, 2022
Added
Nov 4, 2022
Modified
Mar 25, 2026

Description

Gitlab reports: Arbitrary POST requests via special HTML attributes in Jupyter Notebooks DNS Rebinding vulnerability in Irker IRC Gateway integration Missing certificate validation for external CI services Blind SSRF Through Project Import Open redirect vulnerability in Jira Integration Issue link was disclosing the linked issue Service desk email accessible by project non-members Authenticated users can search other users by their private email "External status checks" can be accepted by users below developer access if the user is either author or assignee of the target merge request Deleting packages in bulk from package registries may cause table locks Autocomplete enabled on specific pages Possible SSRF due to not blocking shared address space System notes reveals private project path when Issue is moved to a public project Timeout for pages using Markdown Certain branch names could not be protected

Solution

freebsd-upgrade-package-gitlab-ce
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.