1
0
Fork 1
mirror of https://github.com/NixOS/nixpkgs.git synced 2024-12-25 03:17:13 +00:00
nixpkgs/pkgs
Milan c25756f91c
gitlab: 12.8.1 -> 12.8.2 (#81803)
Includes multiple security fixes mentioned in
https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/
(unfortunately, no CVE numbers as of yet)

 - Directory Traversal to Arbitrary File Read
 - Account Takeover Through Expired Link
 - Server Side Request Forgery Through Deprecated Service
 - Group Two-Factor Authentication Requirement Bypass
 - Stored XSS in Merge Request Pages
 - Stored XSS in Merge Request Submission Form
 - Stored XSS in File View
 - Stored XSS in Grafana Integration
 - Contribution Analytics Exposed to Non-members
 - Incorrect Access Control in Docker Registry via Deploy Tokens
 - Denial of Service via Permission Checks
 - Denial of Service in Design For Public Issue
 - GitHub Tokens Displayed in Plaintext on Integrations Page
 - Incorrect Access Control via LFS Import
 - Unescaped HTML in Header
 - Private Merge Request Titles Leaked via Widget
 - Project Namespace Exposed via Vulnerability Feedback Endpoint
 - Denial of Service Through Recursive Requests
 - Project Authorization Not Being Updated
 - Incorrect Permission Level For Group Invites
 - Disclosure of Private Group Epic Information
 - User IP Address Exposed via Badge images
 - Update postgresql (GitLab Omnibus)
2020-03-05 16:37:21 +01:00
..
applications gitlab: 12.8.1 -> 12.8.2 (#81803) 2020-03-05 16:37:21 +01:00
build-support Merge pull request #81564 from NixOS/fetchpatch-base64 2020-03-04 23:32:29 +01:00
common-updater
data Merge pull request #81705 from r-ryantm/auto-update/papirus-icon-theme 2020-03-04 08:53:32 -03:00
desktops gnomeExtensions.sound-output-device-chooser: 24 -> 25 2020-03-05 02:07:23 +01:00
development Merge pull request #81787 from r-ryantm/auto-update/flyway 2020-03-05 08:04:24 -05:00
games wesnoth: 1.14.10 -> 1.14.11 2020-03-04 19:01:49 +01:00
misc
os-specific Merge pull request #81771 from r-ryantm/auto-update/fwts 2020-03-05 07:18:04 -05:00
servers Merge pull request #81717 from fkstef/fix/adminer-create 2020-03-04 22:18:53 +01:00
shells nix-bash-completions: 0.6.7 -> 0.6.8 (#81019) 2020-03-05 15:08:03 +01:00
stdenv
test
tools Merge pull request #81806 from bhipple/auto-update/procs 2020-03-05 07:59:07 -05:00
top-level Merge pull request #81717 from fkstef/fix/adminer-create 2020-03-04 22:18:53 +01:00