<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-2370 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-2370/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 30 Mar 2026 00:16:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-2370/feed.xml" rel="self" type="application/rss+xml"/><item><title>GitLab Jira Connect Authentication Bypass Vulnerability (CVE-2026-2370)</title><link>https://feed.craftedsignal.io/briefs/2026-03-gitlab-jira-connect-auth-bypass/</link><pubDate>Mon, 30 Mar 2026 00:16:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-gitlab-jira-connect-auth-bypass/</guid><description>GitLab CE/EE versions 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 are vulnerable to improper authorization checks in Jira Connect installations, allowing an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab application.</description><content:encoded>&lt;p>GitLab has addressed a critical vulnerability, CVE-2026-2370, affecting GitLab CE/EE installations with Jira Connect enabled.  This vulnerability impacts versions 14.3 up to 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1. The vulnerability stems from improper authorization checks, which enable an authenticated user with minimal workspace permissions within Jira to potentially obtain GitLab installation credentials. This, in turn, allows the attacker to impersonate the GitLab application…&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>gitlab</category><category>jira</category><category>authentication</category><category>authorization</category><category>cve-2026-2370</category></item></channel></rss>