Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
1
Merge Requests
1
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
nexedi
gitlab-ce
Commits
9fb9cbf5
Commit
9fb9cbf5
authored
Feb 11, 2021
by
GitLab Bot
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Add latest changes from gitlab-org/security/gitlab@13-8-stable-ee
parent
2bfe9c05
Changes
11
Hide whitespace changes
Inline
Side-by-side
Showing
11 changed files
with
16 additions
and
46 deletions
+16
-46
CHANGELOG.md
CHANGELOG.md
+15
-0
GITALY_SERVER_VERSION
GITALY_SERVER_VERSION
+1
-1
changelogs/unreleased/security-cancel-pipelines-for-deleted-project.yml
...eleased/security-cancel-pipelines-for-deleted-project.yml
+0
-5
changelogs/unreleased/security-check-user-access-on-api-mr-read-actions-master.yml
...urity-check-user-access-on-api-mr-read-actions-master.yml
+0
-5
changelogs/unreleased/security-confidential-titles.yml
changelogs/unreleased/security-confidential-titles.yml
+0
-5
changelogs/unreleased/security-fix-unauthenticated-lint.yml
changelogs/unreleased/security-fix-unauthenticated-lint.yml
+0
-5
changelogs/unreleased/security-limit-fscanl.yml
changelogs/unreleased/security-limit-fscanl.yml
+0
-5
changelogs/unreleased/security-limit-invitations.yml
changelogs/unreleased/security-limit-invitations.yml
+0
-5
changelogs/unreleased/security-respect-analytics-enabled-rule-for-project-level-analytics-featu.yml
...lytics-enabled-rule-for-project-level-analytics-featu.yml
+0
-5
changelogs/unreleased/security-ssl-verification-ftc.yml
changelogs/unreleased/security-ssl-verification-ftc.yml
+0
-5
changelogs/unreleased/security-ssrf-prometheus-iap.yml
changelogs/unreleased/security-ssrf-prometheus-iap.yml
+0
-5
No files found.
CHANGELOG.md
View file @
9fb9cbf5
...
...
@@ -2,6 +2,21 @@
documentation
](
doc/development/changelog.md
)
for instructions on adding your own
entry.
## 13.8.4 (2021-02-11)
### Security (9 changes)
-
Cancel running and pending jobs when a project is deleted. !1220
-
Prevent Denial of Service Attack on gitlab-shell.
-
Prevent exposure of confidential issue titles in file browser.
-
Updates authorization for linting API.
-
Check user access on API merge request read actions.
-
Limit daily invitations to groups and projects.
-
Enforce the analytics enabled project setting for project-level analytics features.
-
Perform SSL verification for FortiTokenCloud Integration.
-
Prevent Server-side Request Forgery for Prometheus when secured by Google IAP.
## 13.8.3 (2021-02-05)
### Fixed (2 changes)
...
...
GITALY_SERVER_VERSION
View file @
9fb9cbf5
13.8.3
\ No newline at end of file
13.8.4
\ No newline at end of file
changelogs/unreleased/security-cancel-pipelines-for-deleted-project.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Cancel running and pending jobs when a project is deleted
merge_request
:
1220
author
:
type
:
security
changelogs/unreleased/security-check-user-access-on-api-mr-read-actions-master.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Check user access on API merge request read actions
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-confidential-titles.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Prevent exposure of confidential issue titles in file browser
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-fix-unauthenticated-lint.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Updates authorization for linting API
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-limit-fscanl.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Prevent Denial of Service Attack on gitlab-shell
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-limit-invitations.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Limit daily invitations to groups and projects
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-respect-analytics-enabled-rule-for-project-level-analytics-featu.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Enforce the analytics enabled project setting for project-level analytics features
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-ssl-verification-ftc.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Perform SSL verification for FortiTokenCloud Integration
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-ssrf-prometheus-iap.yml
deleted
100644 → 0
View file @
2bfe9c05
---
title
:
Prevent Server-side Request Forgery for Prometheus when secured by Google IAP
merge_request
:
author
:
type
:
security
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment