Page 93 of 464 results (0.006 seconds)

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed. Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.8. GitLab no estaba comprobando apropiadamente los tokens de autorización, lo cual resultó en la ejecución de la mutación GraphQL • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22209.json https://gitlab.com/gitlab-org/gitlab/-/issues/327155 • CWE-863: Incorrect Authorization •

CVSS: 6.8EPSS: 0%CPEs: 6EXPL: 1

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text, Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 11.6. Las credenciales de Pull Mirror están expuestas, permitiendo que otros mantenedores sean capaz de visualizar las credenciales en texto plano • https://github.com/dannymas/CVE-2021-22206 https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22206.json https://gitlab.com/gitlab-org/gitlab/-/issues/230864 https://hackerone.com/reports/928074 • CWE-312: Cleartext Storage of Sensitive Information •

CVSS: 5.3EPSS: 0%CPEs: 6EXPL: 0

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results. Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.2. Al consultar las ramas del repositorio por medio de API, GitLab ignoraba un parámetro de consulta y devolvía una cantidad considerable de resultados • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22210.json https://gitlab.com/gitlab-org/gitlab/-/issues/322500 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling. Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.7. GitLab Dependency Proxy, bajo determinadas circunstancias, puede hacerse pasar por un usuario, resultando en un manejo de acceso incorrecto • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22211.json https://gitlab.com/gitlab-org/gitlab/-/issues/298847 • CWE-863: Incorrect Authorization •