CVE-2022-1944
https://notcve.org/view.php?id=CVE-2022-1944
06 Jun 2022 — When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs Cuando la función está configurada, una autorización inapropiada en el Terminal Web Interactivo en GitLab CE/EE que afectando a todas las versiones desde la 11.3 anteriores a 14.9.5, 14.10 anteriores a 14.10.4, y 15.0 ant... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.json • CWE-863: Incorrect Authorization •
CVE-2022-1821
https://notcve.org/view.php?id=CVE-2022-1821
06 Jun 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group. Se ha detectado un problema en GitLab CE/EE afectando todas las versiones a partir de 10.8 anteriores a 14.9.5, todas las versiones a partir de la 14.10 anteriores a 14.10.4, todas las versiones a partir de la 15.0 anterior... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1821.json •
CVE-2022-1936
https://notcve.org/view.php?id=CVE-2022-1936
06 Jun 2022 — Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured Una autorización incorrecta en GitLab EE, afectando todas las versiones a partir de 12.0 anteriores a 14.9.5, todas las versiones a partir de 14.10 anteriores a 14.10.4 y todas ... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1936.json • CWE-863: Incorrect Authorization •
CVE-2022-1940
https://notcve.org/view.php?id=CVE-2022-1940
06 Jun 2022 — A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues Una vulnerabilidad de tipo almacenado en la integración de Jira en GitLab EE afectando a todas las versiones desde la 13.11 anteriores a 14.9.5, 14.10 anteriores a 14.10.4 y 15.0 anteriores a 15.0.1, permite a un a... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1940.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-1935
https://notcve.org/view.php?id=CVE-2022-1935
06 Jun 2022 — Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured Una autorización incorrecta en GitLab EE afectando todas las versiones a partir de 12.0 anteriores a 14.9.5, todas las versiones a partir de la 14.10 anteriores a 14.10.4, toda... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1935.json • CWE-863: Incorrect Authorization •