summaryrefslogtreecommitdiff
path: root/spec
Commit message (Expand)AuthorAgeFilesLines
* Merge branch '66641-broken-master-real-http-connections-are-disabled-unregist...Jan Provaznik2019-08-283-16/+24
* Avoid exposing unaccessible repo data upon GFM processingOswaldo Ferreira2019-08-261-2/+70
* Merge branch 'security-hide_merge_request_ids_on_emails-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-262-18/+78
|\
| * Prevent disclosure of merge request id via emailFelipe Artur2019-08-212-18/+78
* | Merge branch 'security-64711-fix-commit-todos-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-261-16/+105
|\ \
| * | Send TODOs for comments on commits correctlyNick Thomas2019-08-231-16/+105
| |/
* | Add captcha if there are multiple failed login attemptsMałgorzata Ksionek2019-08-264-18/+172
* | Merge branch 'security-12-0-enable-image-proxy' into '12-0-stable'GitLab Release Tools Bot2019-08-2610-0/+323
|\ \
| * | Add support for using a Camo proxy serverBrett Walker2019-08-1510-0/+323
| |/
* | Merge branch 'security-60551-fix-upload-scope-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-264-0/+41
|\ \
| * | Queries for Upload should be scoped by modelAdam Hegyi2019-07-114-0/+41
* | | Merge branch 'security-fix-html-injection-for-label-description-ce-12-0' into...GitLab Release Tools Bot2019-08-262-0/+17
|\ \ \
| * | | Fix HTML injection for label descriptionPatrick Derichs2019-08-062-0/+17
| | |/ | |/|
* | | Merge branch 'security-61974-limit-issue-comment-size-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-264-4/+72
|\ \ \
| * | | Limit the size of issuable description and commentsAlexandru Croitor2019-08-224-4/+72
| |/ /
* | | Merge branch 'security-mr-head-pipeline-leak-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-261-4/+26
|\ \ \
| * | | Permission fix for MergeRequestsController#pipeline_statusdrew cimino2019-08-121-4/+26
| |/ /
* | | Merge branch 'security-katex-dos-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-261-2/+4
|\ \ \
| * | | Enforce max chars and max render time in markdown mathMartin Hanzel2019-08-061-2/+4
| |/ /
* | | Merge branch 'security-ssrf-kubernetes-dns-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-263-18/+215
|\ \ \
| * | | Override hostname when connecting via KubeclientThong Kuah2019-08-043-18/+215
| |/ /
* | | Merge branch 'security-2853-prevent-comments-on-private-mrs-12-0' into '12-0-...GitLab Release Tools Bot2019-08-263-71/+357
|\ \ \
| * | | Prevent unauthorised comments on merge requestsAlex Kalderimis2019-08-073-71/+357
| |/ /
* | | Merge branch 'security-fix_jira_ssrf_vulnerability-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-261-0/+5
|\ \ \
| * | | Fix DNS rebind vulnerability for JIRA integrationFelipe Artur2019-08-081-0/+5
| |/ /
* | | Merge branch 'security-project-import-bypass-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-262-15/+135
|\ \ \
| * | | Fix project import restricted visibility bypassGeorge Koltsov2019-08-152-15/+135
| |/ /
* | | Merge branch 'security-sarcila-fix-weak-session-management-12-0' into '12-0-s...GitLab Release Tools Bot2019-08-262-0/+58
|\ \ \
| * | | Add User#will_save_change_to_login? to clear reset_password_tokensSebastian Arcila Valenzuela2019-08-212-0/+58
| |/ /
* | | Merge branch 'security-ci-metrics-permissions-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-261-8/+52
|\ \ \
| * | | Restrict MergeRequests#test_reports to authenticated users with read-access o...drew cimino2019-08-221-8/+52
| |/ /
* | | Merge branch 'security-personal-snippets-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-263-3/+44
|\ \ \
| * | | Add direct upload support for personal snippetsJan Provaznik2019-08-233-3/+44
| |/ /
* | | Merge branch 'security-group-runners-permissions-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-261-38/+167
|\ \ \
| * | | admin_group authorization for Groups::RunnersControllerdrew cimino2019-08-221-38/+167
| |/ /
* | | Re-escape whole HTML content instead of only matchJan Provaznik2019-08-233-0/+36
|/ /
* | Merge branch 'security-fix-badges-leaked-to-unauthorized-users-12-0' into '12...GitLab Release Tools Bot2019-07-241-30/+94
|\ \
| * | Don't display badges when builds are restrictedFabio Pitino2019-06-271-30/+94
* | | Merge branch 'security-github-ssrf-redirect-12-0' into '12-0-stable'GitLab Release Tools Bot2019-07-241-0/+68
|\ \ \
| * | | Do not allow localhost url redirection in GitHub Integrationmanojmj2019-07-091-0/+68
| | |/ | |/|
* | | Merge branch 'security-dns-ssrf-bypass-12-0' into '12-0-stable'GitLab Release Tools Bot2019-07-242-12/+33
|\ \ \
| * | | Fix Server Side Request Forgery mitigation bypassFrancisco Javier López2019-07-042-12/+33
| |/ /
* | | Merge branch 'security-mr-pipeline-permissions-12-0' into '12-0-stable'GitLab Release Tools Bot2019-07-241-4/+94
|\ \ \
| * | | Use MergeRequest#source_project as permissions reference for MergeRequest#all...drew cimino2019-07-051-4/+94
| |/ /
* | | Merge branch 'security-60143-patch-additional-xss-issue-12.0' into '12-0-stable'GitLab Release Tools Bot2019-07-243-42/+151
|\ \ \
| * | | Extract SanitizeNodeLink and apply to WikiLinkFilterKerri Miller2019-07-083-42/+151
| |/ /
* | | Merge branch 'security-remove-take-trigger-ownership-feature-12-0' into '12-0...GitLab Release Tools Bot2019-07-242-51/+0
|\ \ \
| * | | Drop feature to take ownership of a trigger tokenFabio Pitino2019-07-172-51/+0
* | | | Merge branch 'security-2873-restrict-slash-commands-to-users-who-can-log-in-1...GitLab Release Tools Bot2019-07-242-0/+41
|\ \ \ \
| * | | | Restrict slash commands to users who can log inHordur Freyr Yngvason2019-07-122-0/+41
| | |/ / | |/| |