BigW Consortium Gitlab

  1. 11 Jan, 2018 2 commits
  2. 10 Jan, 2018 1 commit
  3. 09 Jan, 2018 2 commits
  4. 08 Jan, 2018 10 commits
    • Merge branch… · fd281365
      Robert Speicher authored
      Merge branch '41293-fix-command-injection-vulnerability-on-system_hook_push-queue-through-web-hook-10-1' into 'security-10-1'
      
      [10.1] Don't allow line breaks on HTTP headers
      
      See merge request gitlab/gitlabhq!2286
      
      (cherry picked from commit 271ef222fa964481379a14a9c07805621a7d52a6)
      
      a30812d3 Don't allow line breaks on HTTP headers
    • Merge branch 'fix/import-rce-10-1' into 'security-10-1' · 62d41f92
      James Lopez authored
      [10.1] Fix RCE via project import mechanism
      
      See merge request gitlab/gitlabhq!2292
      
      (cherry picked from commit 9a399c554268f3ac9e9cd2340600c2df2f5dfa47)
      
      fdbd8d03 Fix RCE via project import mechanism
    • Merge branch 'sh-migrate-can-push-to-deploy-keys-projects-10-1' into 'security-10-1' · 237d2da4
      Douwe Maan authored
      [10.1] Migrate `can_push` column from `keys` to `deploy_keys_project`
      
      See merge request gitlab/gitlabhq!2274
      
      (cherry picked from commit b8ed2ac5bf4a75d0787315e741d4c9aacd36e07e)
      
      5f214517 Backport to 10.1
    • Merge branch '41567-projectfix-10-1' into 'security-10-1' · a9dafaaa
      Sean McGivern authored
      [10.1] backport - check project access on MR create
      
      See merge request gitlab/gitlabhq!2280
      
      (cherry picked from commit 6ca3de3c1e97590f62677227c7eef2f000db766c)
      
      285551b9 check project access on MR create
    • Merge branch 'security-ac/fix-path-traversal-10-1' into 'security-10-1' · 62b0e7f1
      Robert Speicher authored
      [10.1] Fix path traversal in gitlab-ci.yml cache:key
      
      See merge request gitlab/gitlabhq!2272
      
      (cherry picked from commit 991ae1d593e78e7c2484d5fe5b12dfce44a94bc8)
      
      754c83ea Fix path traversal in gitlab-ci.yml cache:key
    • Merge branch 'sh-validate-path-project-import-10-1' into 'security-10-1' · e151f5d5
      Robert Speicher authored
      Validate project path in Gitlab import - 10.1 port
      
      See merge request gitlab/gitlabhq!2266
      
      (cherry picked from commit 14e7f46a07a45bf851178ae6c90c519460bf9736)
      
      13ad8b50 Validate project path in Gitlab import
    • Merge branch 'milestones-finder-order-fix-10-1' into 'security-10-1' · 1da3b9dc
      Robert Speicher authored
      Remove order param from the MilestoneFinder - 10.1 port
      
      See merge request gitlab/gitlabhq!2265
      
      (cherry picked from commit 5f0bb7928b40029a2ced18063c36697e3f8e80c2)
      
      85c6530e Remove order param from the MilestoneFinder
    • Merge branch 'label-xss-10-1' into 'security-10-1' · a7de1343
      Jacob Schatz authored
      [10.1] Fix XSS in issue label dropdown
      
      See merge request gitlab/gitlabhq!2252
      
      (cherry picked from commit 447270c2603dc4962d6aed87baeaeb56c59788ba)
      
      71c6cded Fix XSS in issue label dropdown
      0cc81a51 Move xss_label to smaller test scope
    • Merge branch 'ac/41346-xss-ci-job-output-backport-10-1' into 'security-10-1' · ffccf4a5
      Robert Speicher authored
      [10.1] Fix XSS vulnerability in Pipeline job trace - back port 10.1
      
      See merge request gitlab/gitlabhq!2261
      
      (cherry picked from commit ddb49b9053a31db0dfb93e02be1975549f991695)
      
      dc3d4676 Fix XSS vulnerability in Pipeline job trace
    • Merge branch… · 3a163509
      Sean McGivern authored
      Merge branch 'security-10-1-do-not-expose-passwords-or-tokens-in-service-integrations-api' into 'security-10-1'
      
      Filter out sensitive fields from the project services API
      
      See merge request gitlab/gitlabhq!2283
      
      (cherry picked from commit cde3ae62e8f602b8db4fbdd382fba1a90780be7f)
      
      c958086d Filter out sensitive fields from the project services API
  5. 04 Jan, 2018 1 commit
  6. 18 Dec, 2017 2 commits
  7. 14 Nov, 2017 7 commits
  8. 10 Nov, 2017 15 commits