![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39918
https://notcve.org/view.php?id=CVE-2021-39918
13 Dec 2021 — Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed. Una Autorización Incorrecta en GitLab EE afectando a todas las versiones a partir de 11.1 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2, permite a un usuario a... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39918.json • CWE-863: Incorrect Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-22170
https://notcve.org/view.php?id=CVE-2021-22170
06 Dec 2021 — Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content Suponiendo una violación de la base de datos, los problemas de reúso de nonce en GitLab versión 11.6+ permiten a un atacante descifrar parte del contenido cifrado de la base de datos • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22170.json • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39890
https://notcve.org/view.php?id=CVE-2021-39890
06 Dec 2021 — It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above. Era posible omitir el 2FA para usuarios de LDAP y acceder a algunas páginas específicas con autenticación básica en GitLab versiones 14.1.1 y posteriores • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39890.json • CWE-287: Improper Authentication •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39898
https://notcve.org/view.php?id=CVE-2021-39898
04 Nov 2021 — In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from. En todas las versiones de GitLab CE/EE desde versión 10.6, una exportación de proyecto filtra el valor del token externo de webhook que puede permitir el acceso al proyecto desde el que se exportó • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39898.json • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39905
https://notcve.org/view.php?id=CVE-2021-39905
04 Nov 2021 — An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with Una vulnerabilidad de divulgación de información en la API de GitLab CE/EE desde la versión 8.9.6 permite a un usuario visualizar información básica sobre grupos privados con los que se ha compartido un proyecto público • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39905.json •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39911
https://notcve.org/view.php?id=CVE-2021-39911
04 Nov 2021 — An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers Un defecto de control de acceso inadecuado en todas las versiones de GitLab CE/EE a partir de la 13.9 antes de la 14.2.6, en todas las versiones a partir de la 14.3 antes de la 14.3.4, y en todas las versiones a partir de la... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39907
https://notcve.org/view.php?id=CVE-2021-39907
04 Nov 2021 — A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage. Se ha detectado una posible vulnerabilidad de DOS en GitLab CE/EE a partir de la versión 13.7. La eliminación de los datos EXIF de determinadas imágenes resultaba en un elevado uso de la CPU • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39907.json • CWE-770: Allocation of Resources Without Limits or Throttling •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39904
https://notcve.org/view.php?id=CVE-2021-39904
04 Nov 2021 — An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request Una vulnerabilidad de control de acceso inadecuado en la API GraphQL en todas las versiones de GitLab CE/EE a partir de la 13.1 antes de la 14.2.6, en todas las v... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39904.json • CWE-863: Incorrect Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39895
https://notcve.org/view.php?id=CVE-2021-39895
04 Nov 2021 — In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source. En todas las versiones de GitLab CE/EE desde versión 8.0, un atacante puede configurar las programaciones de tuberías para que estén activas en una exportación d... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39895.json •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-22260
https://notcve.org/view.php?id=CVE-2021-22260
04 Nov 2021 — A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf Una vulnerabilidad de Cross-Site Scripting almacenada en la integración de DataDog en todas las versiones de GitLab CE/EE a partir de la 13.7 antes de la 14.0.9, todas las versiones a partir de la 14... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22260.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •