Page 30 of 397 results (0.009 seconds)

CVSS: 6.5EPSS: 0%CPEs: 6EXPL: 0

18 Jan 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones. Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 12.3. Bajo determinadas condiciones era posible omitir la restricción de IP para proyectos públicos mediante GraphQL permitiendo a usuarios n... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0172.json •

CVSS: 6.5EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager Una vulnerabilidad de consumo no controlado de recursos en GitLab Runner afectando a todas las versiones a partir de 13.7 anteriores a 14.3.6, a todas las versiones a partir de 14.... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39939.json • CWE-400: Uncontrolled Resource Consumption •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates Una falta de autorización en GitLab EE versiones entre la 12.4 y la 14.3.6, entre la 14.4.0 y la 14.4.4, y entre la 14.5.0 y la 14.5.2, permitía a un atacante acceder a las plantillas personalizadas de proyectos y grupos de un usuario • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39930.json • CWE-863: Incorrect Authorization •

CVSS: 5.3EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members Una vulnerabilidad de divulgación de información en GitLab CE/EE versiones 12.0 a 14.3.6, 14.4 a 14.4.4 y 14.5 a 14.5.2, permitía a los no miembros del proyecto visualizar el nombre de la rama por defecto de los proyectos que restringen el acceso al repositorio a lo... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39941.json • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 10.5 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. Los... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39935.json • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 11.0 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39932.json • CWE-20: Improper Input Validation •

CVSS: 6.5EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 12.9 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las ver... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39917.json • CWE-697: Incorrect Comparison •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Un control de acceso inapropiado permite a cualquier miembro del proyecto recuperar la dirección de correo electrónico de la mesa de servicio en GitLab CE/EE versiones a partir de 12.10 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39934.json • CWE-639: Authorization Bypass Through User-Controlled Key •

CVSS: 5.3EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects Un control de acceso inapropiado en la API GraphQL en GitLab CE/EE afectando a todas las versiones a partir de 13.0 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a pa... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39915.json • CWE-668: Exposure of Resource to Wrong Sphere •

CVSS: 6.5EPSS: 0%CPEs: 6EXPL: 0

13 Dec 2021 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 12.10 anteriores a 14.3.6, a todas las versiones a partir de 14.4 anteriores a... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39933.json • CWE-1333: Inefficient Regular Expression Complexity •