Page 73 of 801 results (0.013 seconds)

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

06 Mar 2020 — GitLab 10.7 and later through 12.7.2 has Incorrect Access Control. GitLab versiones 10.7 hasta 12.7.2, presenta un Control de Acceso Incorrecto. • https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released • CWE-269: Improper Privilege Management •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

17 Feb 2020 — In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. En GitLab Enterprise Edition (EE) versiones 12.5.0 hasta 12.7.5, compartir un grupo con un grupo podría otorgar acceso al proyecto a usuarios no autorizados. • https://about.gitlab.com/releases/2020/02/13/critical-security-release-gitlab-12-dot-7-dot-6-released •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

17 Feb 2020 — Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo. Se detectó un Acceso no Autorizado en Container Registry de otros grupos en GitLab Enterpris... • https://about.gitlab.com/blog/categories/releases • CWE-922: Insecure Storage of Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

05 Feb 2020 — An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling. Se detectó un problema en GitLab EE versiones 11.3 y posteriores. Una omisión de GitLab Workhorse podría conllevar a una divulgación de paquetes y archivos mediante el tráfico no autorizado de peticiones. • https://about.gitlab.com/blog/categories/releases •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

05 Feb 2020 — GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. GitLab EE versiones 11.11 y posteriores hasta 12.7.2, permite un Salto de Directorio. • https://about.gitlab.com/blog/categories/releases • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

05 Feb 2020 — GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2). GitLab EE versiones 8.0 hasta 12.7.2, presenta Permisos No Seguros (problema 1 de 2). • https://about.gitlab.com/blog/categories/releases • CWE-276: Incorrect Default Permissions •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

05 Feb 2020 — GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. GitLab EE versiones 8.0 hasta 12.7.2, presenta un Control de Acceso Incorrecto. • https://about.gitlab.com/blog/categories/releases • CWE-862: Missing Authorization •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

05 Feb 2020 — GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure. GitLab EE versiones 8.0 y posteriores hasta 12.7.2, permite una Divulgación de Información. • https://about.gitlab.com/blog/categories/releases •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

05 Feb 2020 — GitLab EE 11.0 and later through 12.7.2 allows XSS. GitLab EE versiones 11.0 y posteriores hasta 12.7.2, permite un ataque de tipo XSS. • https://about.gitlab.com/blog/categories/releases • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

05 Feb 2020 — GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). GitLab EE versión 12.2, presenta Permisos No Seguros (problema 2 de 2). • https://about.gitlab.com/blog/categories/releases • CWE-276: Incorrect Default Permissions •