目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-4672— GitLab 授权问题漏洞

CVSS 4.3 · Medium EPSS 0.24% · P16

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 3

ベンダープロダクトVersion Rangeステータス
GitLabGitLab18.4< 19.0.5affected
19.1< 19.1.3affected
19.2< 19.2.1affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-4672の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Missing Authorization in GitLab
ソース: CVE Program / CVE List V5
脆弱性説明
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
授权机制缺失
ソース: CVE Program / CVE List V5
脆弱性タイトル
GitLab 授权问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
GitLab是美国GitLab公司开源的一个端到端软件开发平台,具有内置的版本控制、问题跟踪、代码审查、CI/CD(持续集成和持续交付)等功能。 GitLab 18.4版本至19.0.5之前版本、19.1版本至19.1.3之前版本和19.2版本至19.2.1之前版本存在授权问题漏洞,该漏洞源于访问控制执行不当,可能导致经过身份验证的具有guest角色的用户访问未授权的测试报告内容。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
GitLabGitLab 18.4 ~ 19.0.5 cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

II. CVE-2026-4672の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-4672のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-4672 补丁与修复 (1)

CVE-2026-4672 其他参考 (1)

Same Patch Batch · GitLab · 2026-07-29 · 13 CVEs total

CVE-2026-62678.5 HIGHInsertion of Sensitive Information Into Sent Data in GitLab
CVE-2026-124368.4 HIGHImproperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
CVE-2026-159757.5 HIGHAllocation of Resources Without Limits or Throttling in GitLab
CVE-2026-131136.5 MEDIUMTime-of-check Time-of-use (TOCTOU) Race Condition in GitLab
CVE-2026-165535.4 MEDIUMInsufficiently Protected Credentials in GitLab
CVE-2026-63365.3 MEDIUMIncorrect Authorization in GitLab
CVE-2026-143414.9 MEDIUMMissing Authorization in GitLab
CVE-2026-30934.7 MEDIUMImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Gi
CVE-2026-143514.3 MEDIUMExposure of Sensitive Information Through Metadata in GitLab
CVE-2026-150774.3 MEDIUMImproper Neutralization of Input Used for LLM Prompting in GitLab
CVE-2026-158314.3 MEDIUMGeneration of Incorrect Security Tokens in GitLab
CVE-2025-145623.1 LOWIncorrect Authorization in GitLab

IV. 関連脆弱性

V. CVE-2026-4672へのコメント

まだコメントはありません


コメントを残す