Page 40 of 253 results (0.004 seconds)

CVSS: 6.4EPSS: 0%CPEs: 6EXPL: 1

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4143.json https://gitlab.com/gitlab-org/gitlab/-/issues/383776 https://hackerone.com/reports/1767639 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2232.json https://gitlab.com/gitlab-org/gitlab/-/issues/408352 https://hackerone.com/reports/1934802 • CWE-1333: Inefficient Regular Expression Complexity •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1825.json https://gitlab.com/gitlab-org/gitlab/-/issues/384035 • CWE-201: Insertion of Sensitive Information Into Sent Data CWE-668: Exposure of Resource to Wrong Sphere •

CVSS: 4.9EPSS: 0%CPEs: 6EXPL: 0

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2485.json https://gitlab.com/gitlab-org/gitlab/-/issues/407830 https://hackerone.com/reports/1934811 • CWE-266: Incorrect Privilege Assignment CWE-269: Improper Privilege Management •

CVSS: 8.7EPSS: 0%CPEs: 4EXPL: 0

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2442.json https://gitlab.com/gitlab-org/gitlab/-/issues/409346 https://hackerone.com/reports/1965750 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •