summaryrefslogtreecommitdiff
path: root/app
Commit message (Expand)AuthorAgeFilesLines
* EE port: Fix private feature Elasticsearch leakMark Chao2019-10-012-2/+8
* Merge branch 'security-sarcila-verify-saml-request-origin-12-1' into '12-1-st...GitLab Release Tools Bot2019-09-261-2/+7
|\
| * Validate that SAML requests are originated from gitlabSebastian Arcila Valenzuela2019-09-161-2/+7
* | Merge branch 'security-xss-mermaid-12-1' into '12-1-stable'GitLab Release Tools Bot2019-09-261-0/+1
|\ \
| * | Upgrade mermaid to prevent xss attackRajat Jain2019-09-101-0/+1
| |/
* | Merge branch 'security-12717-fix-confidential-issue-assignee-visible-to-guest...GitLab Release Tools Bot2019-09-261-1/+1
|\ \
| * | Display only participants that user has permission to seeAlexandru Croitor2019-09-201-1/+1
* | | Merge branch 'security-bypass-email-verification-using-salesforce-12-1' into ...GitLab Release Tools Bot2019-09-261-1/+17
|\ \ \
| * | | Add checking for email_verified keyMałgorzata Ksionek2019-09-111-1/+17
| | |/ | |/|
* | | Merge branch 'security-mermaid-block-12-1' into '12-1-stable'GitLab Release Tools Bot2019-09-261-1/+4
|\ \ \
| * | | Only render fixed number of mermaid blocksRajat Jain2019-09-191-1/+4
| |/ /
* | | Merge branch 'security-12718-project-milestones-disclosed-via-groups-12-1-ce'...GitLab Release Tools Bot2019-09-261-4/+8
|\ \ \
| * | | Hide disabled project milestones in project settings on group levelAlexandru Croitor2019-09-261-4/+8
* | | | Merge branch 'security-64938-dont-disclose-path-12-1-ce' into '12-1-stable'GitLab Release Tools Bot2019-09-261-1/+5
|\ \ \ \
| * | | | Redirect user to root path after unsubscribing from private resourceAlexandru Croitor2019-09-201-1/+5
| | |_|/ | |/| |
* | | | Merge branch 'security-12630-private-system-note-disclosed-in-graphql-12-1-ce...GitLab Release Tools Bot2019-09-262-0/+10
|\ \ \ \
| * | | | Add policy check if cross reference system notes are accessibleAlexandru Croitor2019-09-252-0/+10
| | |/ / | |/| |
* | | | Merge branch 'security-fp-stop-jobs-when-blocking-user-12-1' into '12-1-stable'GitLab Release Tools Bot2019-09-262-0/+23
|\ \ \ \
| * | | | Cancel all running CI jobs when user is blockedFabio Pitino2019-09-242-0/+23
| | |/ / | |/| |
* | | | Merge branch 'security-cross-reference-fix-ce-12-1' into '12-1-stable'GitLab Release Tools Bot2019-09-263-0/+65
|\ \ \ \ | |_|/ / |/| | |
| * | | Filter not accessible label eventsJan Provaznik2019-09-243-0/+65
| |/ /
* | | Merge branch 'ss/fix-sast-failure-on-master-ee' into 'master'Kushal Pandya2019-09-241-1/+1
|/ /
* | Re-add ignore_column for import columnssh-fix-no-downtime-upgrades-ceStan Hu2019-09-171-0/+3
|/
* Return NO_ACCESS if user is nilPatrick Derichs2019-08-281-0/+2
* Merge branch 'security-hide_merge_request_ids_on_emails-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-262-0/+6
|\
| * Prevent disclosure of merge request id via emailFelipe Artur2019-08-212-0/+6
* | Merge branch 'security-64711-fix-commit-todos-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-4/+2
|\ \
| * | Send TODOs for comments on commits correctlyNick Thomas2019-08-231-4/+2
| |/
* | Add captcha if there are multiple failed login attemptsMałgorzata Ksionek2019-08-267-10/+62
* | Merge branch 'security-12-1-enable-image-proxy' into '12-1-stable'GitLab Release Tools Bot2019-08-264-15/+60
|\ \
| * | Add support for using a Camo proxy serverBrett Walker2019-08-154-15/+60
* | | Merge branch 'security-61974-limit-issue-comment-size-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-262-0/+2
|\ \ \
| * | | Limit the size of issuable description and commentsAlexandru Croitor2019-08-222-0/+2
| | |/ | |/|
* | | Merge branch 'security-mr-head-pipeline-leak-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-1/+8
|\ \ \
| * | | Permission fix for MergeRequestsController#pipeline_statusdrew cimino2019-08-121-1/+8
| |/ /
* | | Merge branch 'security-katex-dos-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-18/+128
|\ \ \
| * | | Enforce max chars and max render time in markdown mathMartin Hanzel2019-08-061-18/+128
| |/ /
* | | Merge branch 'security-fix-html-injection-for-label-description-ce-12-1' into...GitLab Release Tools Bot2019-08-262-3/+7
|\ \ \
| * | | Fix HTML injection for label descriptionPatrick Derichs2019-08-052-3/+7
| | |/ | |/|
* | | Merge branch 'security-2853-prevent-comments-on-private-mrs-12-1' into '12-1-...GitLab Release Tools Bot2019-08-262-4/+11
|\ \ \
| * | | Prevent unauthorised comments on merge requestsAlex Kalderimis2019-08-072-4/+11
| | |/ | |/|
* | | Merge branch 'security-epic-notes-api-reveals-historical-info-ce-12-1' into '...GitLab Release Tools Bot2019-08-263-2/+6
|\ \ \
| * | | Filter out old system notes for epicsPatrick Derichs2019-08-093-2/+6
| |/ /
* | | Merge branch 'security-fix_jira_ssrf_vulnerability-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-1/+6
|\ \ \
| * | | Fix DNS rebind vulnerability for JIRA integrationFelipe Artur2019-08-081-1/+6
| |/ /
* | | Merge branch 'security-id-filter-timeline-activities-for-guests-12-1' into '1...GitLab Release Tools Bot2019-08-261-1/+1
|\ \ \
| * | | Add merge note type as cross referenceIgor Drozdov2019-08-141-1/+1
| |/ /
* | | Merge branch 'security-project-import-bypass-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-11/+16
|\ \ \
| * | | Fix project import restricted visibility bypassGeorge Koltsov2019-08-151-11/+16
| |/ /
* | | Merge branch 'security-add-job-activity-limit-ce-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-262-1/+3
|\ \ \