CVE-2022-2229
https://notcve.org/view.php?id=CVE-2022-2229
01 Jul 2022 — An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of. Un problema de autorización inapropiada en GitLab CE/EE afectando a todas las versiones desde la 13.7 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1 permite a un atacante extraer el va... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2229.json •
CVE-2022-2228
https://notcve.org/view.php?id=CVE-2022-2228
01 Jul 2022 — Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range Una exposición de información en GitLab EE afectando a todas las versiones desde la 12.0 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1 permite a un... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2228.json •
CVE-2022-1999
https://notcve.org/view.php?id=CVE-2022-1999
01 Jul 2022 — An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones desde la 8.13 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1. Bajo determinadas condiciones, usando la API REST un usuario no privilegiado podía cambiar l... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1999.json •
CVE-2022-1981
https://notcve.org/view.php?id=CVE-2022-1981
01 Jul 2022 — An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list. Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de la 12.2 anteriore... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1981.json • CWE-863: Incorrect Authorization •
CVE-2022-1983
https://notcve.org/view.php?id=CVE-2022-1983
01 Jul 2022 — Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured. Una autorización incorrecta en GitLab EE afectando a todas las versiones desde la 10.7 anteriores a 14.10.5, 15.0 anteriores a 15.0.4 y 15.1 anteriores a 15.1.1, permitía a un ataca... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1983.json • CWE-863: Incorrect Authorization •
CVE-2022-2230
https://notcve.org/view.php?id=CVE-2022-2230
01 Jul 2022 — A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf. Una vulnerabilidad de tipo Cross-Site Scripting almacenada en la página de configuración del proyecto en GitLab CE/EE afectando a todas las versiones desde 14.4 anteriores a 14.10.5, 15.0 anteriores a 15.0.4, y 15.1 anteriores a 15.1.1,... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2230.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-2227
https://notcve.org/view.php?id=CVE-2022-2227
01 Jul 2022 — Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions Un control de acceso inapropiado en la API de trabajos del corredor en GitLab CE/EE afectando a todas las versiones anteriores a 14.10.5, 15.0 anteriores a 15.0.4, y 15.1 anteriores a 15.1.1, permite a un mantenedor anterior de un proy... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2227.json • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2022-2243
https://notcve.org/view.php?id=CVE-2022-2243
01 Jul 2022 — An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2243.json • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2022-2235
https://notcve.org/view.php?id=CVE-2022-2235
01 Jul 2022 — Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link Un saneamiento insuficiente en el rastreador de problemas externo de GitLab EE afectando a todas las versiones desde la 14.5 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4, y la 15.1 anteriores a 15.1.1 permite a un atacante llevar a cabo... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2235.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-2185
https://notcve.org/view.php?id=CVE-2022-2185
01 Jul 2022 — A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution. Se ha descubierto un problema crítico en GitLab que afecta a todas las versiones a partir de la 14.0 anterior a la 14.10.5, la 15.0 anterior a la 15.0.4 y la 15.1 anterior a la 15.1.1, en el que un usuario autenticado y aut... • https://github.com/ESUAdmin/CVE-2022-2185 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •