Page 53 of 502 results (0.009 seconds)

CVSS: 4.9EPSS: 0%CPEs: 6EXPL: 0

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access. Para GitLab versiones anteriores a 13.0.12, 13.1.6, 13.2.3 después que ocurre una transferencia de grupo, los miembros de un grupo principal mantienen su nivel de acceso en el subgrupo conllevando a un acceso inapropiado • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13282.json https://gitlab.com/gitlab-org/gitlab/-/issues/202687 https://hackerone.com/reports/790786 • CWE-281: Improper Preservation of Permissions •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page En GitLab versiones anteriores a 13.0.12, 13.1.6, y 13.2.3, se usó un control de acceso inadecuado en la página de Aplicaciones • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13290.json https://gitlab.com/gitlab-org/gitlab/-/issues/32291 https://hackerone.com/reports/691477 • CWE-287: Improper Authentication •

CVSS: 5.5EPSS: 0%CPEs: 3EXPL: 0

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application. En GitLab versiones anteriores a 13.0.12, 13.1.6 y 13.2.3, los otorgamientos de acceso no fueron revocados cuando un usuario revocaba el acceso a una aplicación • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13294.json https://gitlab.com/gitlab-org/gitlab/-/issues/26147 https://hackerone.com/reports/469728 •

CVSS: 7.1EPSS: 0%CPEs: 3EXPL: 0

In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash. En GitLab versiones anteriores a 13.0.12, 13.1.6 y 13.2.3, el uso de una rama con un nombre hexadecimal podría anular un hash existente • https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13293.json https://gitlab.com/gitlab-org/gitlab/-/issues/202690 https://hackerone.com/reports/790634 •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint. GitLab EE versiones 11.3 hasta 13.1.2, presenta un Control de Acceso Incorrecto debido al endpoint de carga del paquete Maven • https://about.gitlab.com/releases/2020/07/06/critical-security-release-gitlab-13-1-3-released https://about.gitlab.com/releases/categories/releases https://gitlab.com/gitlab-org/gitlab/-/issues/225259 •