CVE-2021-22196
https://notcve.org/view.php?id=CVE-2021-22196
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name. Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.4. Era posible explotar una vulnerabilidad de tipo cross-site-scripting almacenada en una petición de combinación por medio de un nombre de rama diseñado específicamente. • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22196.json https://gitlab.com/gitlab-org/gitlab/-/issues/254710 https://hackerone.com/reports/977697 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-22177
https://notcve.org/view.php?id=CVE-2021-22177
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command. Se identificó una DoS potencial en gitlab-shell en GitLab CE/EE versiones 12.6.0 o superiores, lo que permite a un atacante aumentar la utilización de recursos del servidor por medio del comando gitlab-shell. • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22177.json https://gitlab.com/gitlab-org/gitlab/-/issues/238988 https://hackerone.com/reports/953444 • CWE-400: Uncontrolled Resource Consumption •
CVE-2021-22184
https://notcve.org/view.php?id=CVE-2021-22184
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted. Un problema de divulgación de información en GitLab desde la versión 12.8, permitió a un usuario con acceso a los registros del servidor visualizar información confidencial que no se redactó apropiadamente. • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22184.json https://gitlab.com/gitlab-org/gitlab/-/issues/281676 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2021-22180
https://notcve.org/view.php?id=CVE-2021-22180
An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages. Se ha detectado un problema en GitLab que afecta a todas las versiones desde 13.4. Un control de acceso inapropiado permite a usuarios no autorizados acceder a los detalles de las páginas analíticas. • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22180.json https://gitlab.com/gitlab-org/gitlab/-/issues/295662 https://hackerone.com/reports/1064645 • CWE-425: Direct Request ('Forced Browsing') •
CVE-2021-22194
https://notcve.org/view.php?id=CVE-2021-22194
In all versions of GitLab, marshalled session keys were being stored in Redis. En todas las versiones de GitLab, las claves de sesión marshalled estaban siendo almacenadas en Redis • https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22194.json https://gitlab.com/gitlab-org/gitlab/-/issues/262107 • CWE-312: Cleartext Storage of Sensitive Information •