Page 4 of 111 results (0.013 seconds)

CVSS: 6.8EPSS: 0%CPEs: 3EXPL: 1

12 Dec 2024 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim. • https://gitlab.com/gitlab-org/gitlab/-/issues/494694 • CWE-270: Privilege Context Switching Error •

CVSS: 4.0EPSS: 0%CPEs: 3EXPL: 0

12 Dec 2024 — An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs. • https://gitlab.com/gitlab-org/gitlab/-/issues/475211 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

26 Nov 2024 — An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances. • https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#information-disclosure-through-an-api-endpoint • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 1

26 Nov 2024 — A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch. • https://gitlab.com/gitlab-org/gitlab/-/issues/443559 • CWE-407: Inefficient Algorithmic Complexity •

CVSS: 7.7EPSS: 0%CPEs: 3EXPL: 0

26 Nov 2024 — An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes. • https://gitlab.com/gitlab-org/gitlab/-/issues/501528 • CWE-863: Incorrect Authorization •

CVSS: 8.2EPSS: 0%CPEs: 3EXPL: 1

26 Nov 2024 — An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges. • https://gitlab.com/gitlab-org/gitlab/-/issues/480494 • CWE-862: Missing Authorization •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 1

26 Nov 2024 — An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry. • https://gitlab.com/gitlab-org/gitlab/-/issues/480706 • CWE-407: Inefficient Algorithmic Complexity •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 1

26 Nov 2024 — A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file. • https://gitlab.com/gitlab-org/gitlab/-/issues/480900 • CWE-407: Inefficient Algorithmic Complexity •

CVSS: 4.2EPSS: 0%CPEs: 3EXPL: 0

26 Nov 2024 — An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results. • https://gitlab.com/gitlab-org/gitlab/-/issues/456922 • CWE-613: Insufficient Session Expiration •

CVSS: 3.1EPSS: 0%CPEs: 3EXPL: 1

14 Nov 2024 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks. An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions sta... • https://gitlab.com/gitlab-org/gitlab/-/issues/498257 • CWE-708: Incorrect Ownership Assignment •