CVE-2022-0152
https://notcve.org/view.php?id=CVE-2022-0152
18 Jan 2022 — An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API. Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 13.10 anteriores a 14.4.5, todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, todas las versiones a partir de la 14.6.0 ant... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0152.json • CWE-862: Missing Authorization •
CVE-2021-39927
https://notcve.org/view.php?id=CVE-2021-39927
18 Jan 2022 — Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443 Las protecciones contra la falsificación de solicitudes del lado del servidor en las versiones de GitLab CE/EE entre 8.4 y 14.4.4, entre 14.5.0 y 14.5.2, y entre 14.6.0 y 14.6.1 fallaban en la protección contra los at... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39927.json • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2022-0172
https://notcve.org/view.php?id=CVE-2022-0172
18 Jan 2022 — An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones. Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 12.3. Bajo determinadas condiciones era posible omitir la restricción de IP para proyectos públicos mediante GraphQL permitiendo a usuarios n... • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0172.json •
CVE-2021-39930
https://notcve.org/view.php?id=CVE-2021-39930
13 Dec 2021 — Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates Una falta de autorización en GitLab EE versiones entre la 12.4 y la 14.3.6, entre la 14.4.0 y la 14.4.4, y entre la 14.5.0 y la 14.5.2, permitía a un atacante acceder a las plantillas personalizadas de proyectos y grupos de un usuario • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39930.json • CWE-863: Incorrect Authorization •
CVE-2021-39939
https://notcve.org/view.php?id=CVE-2021-39939
13 Dec 2021 — An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager Una vulnerabilidad de consumo no controlado de recursos en GitLab Runner afectando a todas las versiones a partir de 13.7 anteriores a 14.3.6, a todas las versiones a partir de 14.... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39939.json • CWE-400: Uncontrolled Resource Consumption •
CVE-2021-39941
https://notcve.org/view.php?id=CVE-2021-39941
13 Dec 2021 — An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members Una vulnerabilidad de divulgación de información en GitLab CE/EE versiones 12.0 a 14.3.6, 14.4 a 14.4.4 y 14.5 a 14.5.2, permitía a los no miembros del proyecto visualizar el nombre de la rama por defecto de los proyectos que restringen el acceso al repositorio a lo... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39941.json • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2021-39935
https://notcve.org/view.php?id=CVE-2021-39935
13 Dec 2021 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 10.5 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. Los... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39935.json • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2021-39932
https://notcve.org/view.php?id=CVE-2021-39932
13 Dec 2021 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 11.0 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39932.json • CWE-20: Improper Input Validation •
CVE-2021-39917
https://notcve.org/view.php?id=CVE-2021-39917
13 Dec 2021 — An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack. Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 12.9 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las ver... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39917.json • CWE-697: Incorrect Comparison •
CVE-2021-39934
https://notcve.org/view.php?id=CVE-2021-39934
13 Dec 2021 — Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Un control de acceso inapropiado permite a cualquier miembro del proyecto recuperar la dirección de correo electrónico de la mesa de servicio en GitLab CE/EE versiones a partir de 12.10 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas... • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39934.json • CWE-639: Authorization Bypass Through User-Controlled Key •