GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "8.17.7"
},
{
"introduced": "0"
},
{
"last_affected": "8.17.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.10"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.10"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.11"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.11"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.12"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.12"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.2.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.6"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.7"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.8"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "9.4.3"
}
]
}