Page 85 of 1071 results (0.024 seconds)

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

05 Jan 2020 — GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext. GitLab EE versiones 8.4 hasta 12.5, 12.4.3 y 12.3.6, almacenaron varios tokens en texto plano. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-312: Cleartext Storage of Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

05 Jan 2020 — GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits. GitLab EE versiones 12.3 hasta 12.5, 12.4.3 y 12.3.6, permite una Denegación de Servicio. Ciertos caracteres hacían imposible crear, editar o visualizar problemas y confirmaciones. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-755: Improper Handling of Exceptional Conditions •

CVSS: 5.8EPSS: 0%CPEs: 3EXPL: 0

05 Jan 2020 — GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API. GitLab EE versiones 8.14 hasta las versiones 12.5, 12.4.3 y 12.3.6, tiene un Control de Acceso Incorrecto. Después de que un proyecto cambió a privado, los repositorios previamente bifurcados podían aún ser capaces de obtener información sobre el proyecto privado mediante la API. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released •

CVSS: 4.9EPSS: 0%CPEs: 1EXPL: 0

03 Jan 2020 — GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure. GitLab Enterprise Edition (EE) versiones 9.0 y posteriores hasta la versión 12.5, permite una Divulgación de Información. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-522: Insufficiently Protected Credentials •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

03 Jan 2020 — GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control. GitLab Enterprise Edition (EE) versiones 8.90 y posteriores hasta la versión 12.5, tiene un Control de Acceso Incorrecto. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

03 Jan 2020 — GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions. GitLab Enterprise Edition (EE) versiones 8.2 y posteriores hasta la versíon 12.5, tiene Permisos No Seguros. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

03 Jan 2020 — GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions. GitLab Enterprise Edition (EE) versiones 11.9 y posteriores hasta la versión 12.5, tiene Permisos No Seguros. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

03 Jan 2020 — GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF. GitLab Enterprise Edition (EE) versiones 6.7 y posteriores hasta la 12.5, permite un ataque de tipo SSRF. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

03 Jan 2020 — GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2). GitLab Community Edition (CE) and Enterprise Edition (EE) versiones hasta la versión 12.5, tiene un Control de Acceso Incorrecto (problema 2 de 2). • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

03 Jan 2020 — GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR). GitLab Enterprise Edition (EE) versiones 11.3 y posteriores hasta la versión 12.5, permite una Referencia de Objeto Directo No Seguro (IDOR). • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-639: Authorization Bypass Through User-Controlled Key •