CVE-2020-13330
https://notcve.org/view.php?id=CVE-2020-13330
An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature. Se ha detectado un problema en GitLab que afecta a versiones anteriores a 12.10.13. GitLab era vulnerable a un ataque de tipo XSS almacenado al importar la funcionalidad de proyecto Bitbucket • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13330.json https://gitlab.com/gitlab-org/gitlab/issues/30017 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-13329
https://notcve.org/view.php?id=CVE-2020-13329
An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature. Se ha detectado un problema en GitLab que afecta a versiones de 12.6.2 anteriores a 12.10.13. GitLab era vulnerable a un ataque de tipo XSS almacenado en la funcionalidad blob view • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13329.json https://gitlab.com/gitlab-org/gitlab/-/issues/208685 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-13328
https://notcve.org/view.php?id=CVE-2020-13328
An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API. Se ha detectado un problema en GitLab que afecta a versiones anteriores a 13.1.2, 13.0.8 y 12.10.13. GitLab era vulnerable a un ataque de tipo XSS almacenado por medio del uso de la API de archivos PyPi • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13328.json https://gitlab.com/gitlab-org/gitlab/-/issues/215640 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-13320
https://notcve.org/view.php?id=CVE-2020-13320
An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard. Se detectó un problema en GitLab versiones anteriores a 12.10.13, que permitía a un miembro del proyecto con permisos limitados visualizar el panel de seguridad del proyecto • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13320.json https://gitlab.com/gitlab-org/gitlab/-/issues/215044 •
CVE-2020-13322
https://notcve.org/view.php?id=CVE-2020-13322
A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens. Se detectó una vulnerabilidad en de GitLab posteriores a 12.9. Debido a una comprobación de permisos inapropiada, un usuario no autorizado puede crear y eliminar tokens de implementación • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13322.json https://gitlab.com/gitlab-org/gitlab/-/issues/212469 • CWE-863: Incorrect Authorization •