Gitlab CI v12.2.3 Release Notes
Release Date: 2019-08-28 // over 4 years ago-
๐ Security (22 changes)
- ๐ Ensure only authorised users can create notes on Merge Requests and Issues.
- Gitaly: ignore git redirects.
- Add :login_recaptcha_protection_enabled setting to prevent bots from brute-force attacks.
- Speed up regexp in namespace format by failing fast after reaching maximum namespace depth.
- Limit the size of issuable description and comments.
- Send TODOs for comments on commits correctly.
- ๐ Restrict MergeRequests#test_reports to authenticated users with read-access on Builds.
- โ Added image proxy to mitigate potential stealing of IP addresses.
- Filter out old system notes for epics in notes api endpoint response.
- Avoid exposing unaccessible repo data upon GFM post processing.
- ๐ Fix HTML injection for label description.
- ๐ Make sure HTML text is always escaped when replacing label/milestone references.
- Prevent DNS rebind on JIRA service integration.
- ๐ Use admin_group authorization in Groups::RunnersController.
- ๐ Prevent disclosure of merge request ID via email.
- ๐ Show cross-referenced MR-id in issues' activities only to authorized users.
- Enforce max chars and max render time in markdown math.
- ๐ Check permissions before responding in MergeController#pipeline_status.
- โ Remove EXIF from users/personal snippet uploads.
- ๐ Fix project import restricted visibility bypass via API.
- ๐ Fix weak session management by clearing password reset tokens after login (username/email) are updated.
- ๐ Fix SSRF via DNS rebinding in Kubernetes Integration.