CVE-2022-1954
https://notcve.org/view.php?id=CVE-2022-1954
01 Jul 2022 — A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers Una vulnerabilidad de Denegación de Servicio por Expresiones Regulares en GitLab CE/EE que afecta a todas las versiones desde la 1.0.2 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite a un atacant... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1954.json • CWE-1333: Inefficient Regular Expression Complexity •
CVE-2022-1963
https://notcve.org/view.php?id=CVE-2022-1963
01 Jul 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 13.4 anteriores a 14.10.5, a todas las versiones a partir de la 15.0 anteriores a 15.0.4, a todas ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1963.json •
CVE-2022-2270
https://notcve.org/view.php?id=CVE-2022-2270
01 Jul 2022 — An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification. Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 12.4 anteriores a 14.10.5, todas las versiones a partir de la 15.0 anteriores a 15.0.4, todas las versiones a partir de la 15.1 anteriores a 15.1.1. GitL... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2270.json • CWE-276: Incorrect Default Permissions •
CVE-2022-2229
https://notcve.org/view.php?id=CVE-2022-2229
01 Jul 2022 — An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of. Un problema de autorización inapropiada en GitLab CE/EE afectando a todas las versiones desde la 13.7 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1 permite a un atacante extraer el va... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2229.json •
CVE-2022-2228
https://notcve.org/view.php?id=CVE-2022-2228
01 Jul 2022 — Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range Una exposición de información en GitLab EE afectando a todas las versiones desde la 12.0 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1 permite a un... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2228.json •
CVE-2022-1999
https://notcve.org/view.php?id=CVE-2022-1999
01 Jul 2022 — An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones desde la 8.13 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1. Bajo determinadas condiciones, usando la API REST un usuario no privilegiado podía cambiar l... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1999.json •
CVE-2022-1981
https://notcve.org/view.php?id=CVE-2022-1981
01 Jul 2022 — An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list. Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de la 12.2 anteriore... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1981.json • CWE-863: Incorrect Authorization •
CVE-2022-1983
https://notcve.org/view.php?id=CVE-2022-1983
01 Jul 2022 — Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured. Una autorización incorrecta en GitLab EE afectando a todas las versiones desde la 10.7 anteriores a 14.10.5, 15.0 anteriores a 15.0.4 y 15.1 anteriores a 15.1.1, permitía a un ataca... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1983.json • CWE-863: Incorrect Authorization •
CVE-2022-2230
https://notcve.org/view.php?id=CVE-2022-2230
01 Jul 2022 — A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf. Una vulnerabilidad de tipo Cross-Site Scripting almacenada en la página de configuración del proyecto en GitLab CE/EE afectando a todas las versiones desde 14.4 anteriores a 14.10.5, 15.0 anteriores a 15.0.4, y 15.1 anteriores a 15.1.1,... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2230.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-2227
https://notcve.org/view.php?id=CVE-2022-2227
01 Jul 2022 — Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions Un control de acceso inapropiado en la API de trabajos del corredor en GitLab CE/EE afectando a todas las versiones anteriores a 14.10.5, 15.0 anteriores a 15.0.4, y 15.1 anteriores a 15.1.1, permite a un mantenedor anterior de un proy... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2227.json • CWE-732: Incorrect Permission Assignment for Critical Resource •