Page 40 of 1067 results (0.026 seconds)

CVSS: 5.0EPSS: 0%CPEs: 6EXPL: 0

01 Jul 2022 — An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2243.json • CWE-639: Authorization Bypass Through User-Controlled Key •

CVSS: 8.7EPSS: 0%CPEs: 3EXPL: 0

01 Jul 2022 — Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link Un saneamiento insuficiente en el rastreador de problemas externo de GitLab EE afectando a todas las versiones desde la 14.5 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4, y la 15.1 anteriores a 15.1.1 permite a un atacante llevar a cabo... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2235.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.9EPSS: 94%CPEs: 6EXPL: 2

01 Jul 2022 — A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution. Se ha descubierto un problema crítico en GitLab que afecta a todas las versiones a partir de la 14.0 anterior a la 14.10.5, la 15.0 anterior a la 15.0.4 y la 15.1 anterior a la 15.1.1, en el que un usuario autenticado y aut... • https://github.com/ESUAdmin/CVE-2022-2185 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

01 Jul 2022 — An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases. Una vulnerabilidad de divulgación de información en GitLab EE afectando a todas las versiones a partir de la 12.5 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite una divulgación de los títulos de las versiones si los hito... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2281.json •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

01 Jul 2022 — An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature. Una vulnerabilidad de autorización inapropiada en GitLab EE/CE afectando a todas las versiones desde la 14.8 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite a miembros del proyecto con rol de reportero administrar probl... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2244.json •

CVSS: 6.1EPSS: 0%CPEs: 6EXPL: 0

01 Jul 2022 — An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL. Una vulnerabilidad de redireccionamiento abierto en GitLab EE/CE afectando a todas las versiones desde la 11.1 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite a un atacante redirigir a usuarios a una ubicación arbitraria si confían en la UR... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2250.json • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 9.9EPSS: 0%CPEs: 3EXPL: 0

06 Jun 2022 — An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in t... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1680.json •

CVSS: 4.0EPSS: 0%CPEs: 6EXPL: 0

06 Jun 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json •

CVSS: 7.1EPSS: 0%CPEs: 6EXPL: 0

06 Jun 2022 — When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs Cuando la función está configurada, una autorización inapropiada en el Terminal Web Interactivo en GitLab CE/EE que afectando a todas las versiones desde la 11.3 anteriores a 14.9.5, 14.10 anteriores a 14.10.4, y 15.0 ant... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.json • CWE-863: Incorrect Authorization •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 1

06 Jun 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group. Se ha detectado un problema en GitLab CE/EE afectando todas las versiones a partir de 10.8 anteriores a 14.9.5, todas las versiones a partir de la 14.10 anteriores a 14.10.4, todas las versiones a partir de la 15.0 anterior... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1821.json •