References https://nic.seu.edu.cn/info/1047/1226.htm https://www.aqtd.com/nd.jsp?id=7389 https://www.venustech.com.cn/new_type/aqtg/20241127/28139.html https://wlaq.njupt.edu.cn/2024/1202/c14800a275312/page.htm https://www.cnvd.org.cn/flaw/show/CNVD-2020-65167 https://xxzx.tstc.edu.cn/info/1029/1137.htm https://wlaq.dlut.edu.cn/info/1095/5534.htm https://avd.aliyun.com/detail?id=AVD-2023-1071 https://www.venustech.com.cn/new_type/aqtg/20240711/27732.html https://github.com/advisories/GHSA-8xr4-8v2f-pqrx
Related VulnerabilitiesPoCCVE-2026-85706: GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File ReadGitLab CE/EE /api/graphql 未授权访问漏洞(CVE-2026-19478)PoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationPoCCVE-2021-22175: GitLab CI Lint API - Server-Side Request ForgeryGitLab CE/EE GraphQL 身份验证缺陷漏洞GitLab CE/EE 资源分配控制不当漏洞 可导致拒绝服务gitlab-api-user-enum: GitLab - User Information Disclosure Via Open APIPoCCVE-2024-45409: GitLab - SAML Authentication BypassPoCCVE-2025-25291: GitLab - SAML Authentication BypassPoCCVE-2019-6793: GitLab Enterprise Edition - Server-Side Request ForgeryPoCCVE-2020-2096: Jenkins Gitlab Hook <=1.4.2 - Cross-Site ScriptingPoCCVE-2020-26413: Gitlab CE/EE 13.4 - 13.6.2 - Information DisclosurePoCCVE-2021-22205: GitLab CE/EE - Remote Code Execution