Page 38 of 1048 results (0.010 seconds)

CVSS: 5.3EPSS: 0%CPEs: 6EXPL: 0

05 Aug 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor emails due to improper data handling in the Datadog integration. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 9.3 anteriores a 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4 y a todas las versiones a partir de 15.2 anteri... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2534.json •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

05 Aug 2022 — An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a la 15.0.5, a todas las versiones a partir de 15.1 anteriores... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2303.json • CWE-287: Improper Authentication •

CVSS: 9.4EPSS: 0%CPEs: 6EXPL: 0

05 Aug 2022 — An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a la 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4 y a todas las versiones a p... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2326.json • CWE-863: Incorrect Authorization •

CVSS: 4.7EPSS: 0%CPEs: 6EXPL: 0

05 Aug 2022 — A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited. Una falta de borrado en cascada en GitLab CE/EE afectando a todas las versiones a partir de 13.0 anteriores a 15.0.5, a todas las versiones a partir de 15.1 anteriore... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2307.json • CWE-459: Incomplete Cleanup •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

05 Aug 2022 — An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author. Un problema en las suscripciones a pipelines en GitLab EE afectando a todas las versiones desde la 12.8 anteriores a 15.0.5, la 15.1 anteriores a 15.1.4 y la 15.2 anteriores a 15.2.1, desencadena nuevos pipelines con la persona que creó la etiqu... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2498.json • CWE-269: Improper Privilege Management •

CVSS: 4.9EPSS: 0%CPEs: 6EXPL: 0

05 Aug 2022 — An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a la 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4 y a todas las vers... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2456.json •

CVSS: 6.2EPSS: 0%CPEs: 6EXPL: 0

05 Aug 2022 — Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project. Una comprobación insuficiente en GitLab CE/EE afectando a todas las versiones a partir de 12.10 anteriores a 15.0.5, la 15.1 anteriores a... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2417.json • CWE-20: Improper Input Validation •

CVSS: 5.3EPSS: 0%CPEs: 6EXPL: 0

05 Aug 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 14.6 anterior a la 15.0.5, la 15.1 anterior a la 15.1.4 y la 15.2 anterior a la 15.2.1, que permitía a un miembro del proyecto filtrar las incidencias por contacto y organización • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2539.json •

CVSS: 6.8EPSS: 0%CPEs: 6EXPL: 0

05 Aug 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 15.0 anteriores a 15.0.5, todas las versiones a partir de 15.1 anteriores a 15.1.4, todas las vers... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2512.json •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

05 Aug 2022 — An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues. Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de 13.10 anteriores a 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4, a todas ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2499.json • CWE-639: Authorization Bypass Through User-Controlled Key •