1
0
Fork 1
mirror of https://github.com/NixOS/nixpkgs.git synced 2024-11-22 13:41:26 +00:00
nixpkgs/pkgs/applications/version-management/gitlab
Milan c25756f91c
gitlab: 12.8.1 -> 12.8.2 (#81803)
Includes multiple security fixes mentioned in
https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/
(unfortunately, no CVE numbers as of yet)

 - Directory Traversal to Arbitrary File Read
 - Account Takeover Through Expired Link
 - Server Side Request Forgery Through Deprecated Service
 - Group Two-Factor Authentication Requirement Bypass
 - Stored XSS in Merge Request Pages
 - Stored XSS in Merge Request Submission Form
 - Stored XSS in File View
 - Stored XSS in Grafana Integration
 - Contribution Analytics Exposed to Non-members
 - Incorrect Access Control in Docker Registry via Deploy Tokens
 - Denial of Service via Permission Checks
 - Denial of Service in Design For Public Issue
 - GitHub Tokens Displayed in Plaintext on Integrations Page
 - Incorrect Access Control via LFS Import
 - Unescaped HTML in Header
 - Private Merge Request Titles Leaked via Widget
 - Project Namespace Exposed via Vulnerability Feedback Endpoint
 - Denial of Service Through Recursive Requests
 - Project Authorization Not Being Updated
 - Incorrect Permission Level For Group Invites
 - Disclosure of Private Group Epic Information
 - User IP Address Exposed via Badge images
 - Update postgresql (GitLab Omnibus)
2020-03-05 16:37:21 +01:00
..
gitaly gitlab: 12.8.1 -> 12.8.2 (#81803) 2020-03-05 16:37:21 +01:00
gitlab-shell gitlab-shell: Change name from gitlab-shell-go to gitlab-shell 2020-03-03 21:19:01 +01:00
gitlab-workhorse gitlab-workhorse: 8.20.0 -> 8.21.0 2020-03-03 21:19:01 +01:00
rubyEnv gitlab: 12.7.6 -> 12.8.1 2020-03-03 21:19:01 +01:00
data.json gitlab: 12.8.1 -> 12.8.2 (#81803) 2020-03-05 16:37:21 +01:00
default.nix gitlab: fix asset building for CE 2020-01-13 15:57:11 +01:00
fix-grpc-ar.patch gitlab: 11.10.8 -> 12.0.3 2019-07-14 23:03:39 +02:00
remove-hardcoded-locations.patch gitlab: 12.3.5 -> 12.4.0 2019-10-28 14:56:37 +01:00
reset_token.rake gitlab: add rake task to delete tokens 2017-03-21 13:16:54 +01:00
update.py gitlab: update.py: Get go deps for gitlab-shell from the root dir 2019-12-23 00:26:28 +01:00
yarnPkgs.nix gitlab: 12.7.6 -> 12.8.1 2020-03-03 21:19:01 +01:00