Количество 5 336
Количество 5 336
CVE-2021-39915
Improper access control in the GraphQL API in GitLab CE/EE affecting a ...
CVE-2021-39914
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user
CVE-2021-39914
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user
CVE-2021-39914
A regular expression denial of service issue in GitLab versions 8.13 t ...
CVE-2021-39913
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
CVE-2021-39913
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
CVE-2021-39913
Accidental logging of system root password in the migration log in all ...
CVE-2021-39912
A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.
CVE-2021-39912
A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.
CVE-2021-39912
A potential DoS vulnerability was discovered in GitLab CE/EE starting ...
CVE-2021-39911
An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers
CVE-2021-39911
An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers
CVE-2021-39911
An improper access control flaw in all versions of GitLab CE/EE starti ...
CVE-2021-39910
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.
CVE-2021-39910
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.
CVE-2021-39910
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2021-39909
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances
CVE-2021-39909
Lack of email address ownership verification in the CODEOWNERS feature ...
CVE-2021-39908
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.
CVE-2021-39908
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39915 Improper access control in the GraphQL API in GitLab CE/EE affecting a ... | CVSS3: 5.3 | 0% Низкий | около 4 лет назад | |
CVE-2021-39914 A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user | CVSS3: 3.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39914 A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user | CVSS3: 3.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39914 A regular expression denial of service issue in GitLab versions 8.13 t ... | CVSS3: 3.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39913 Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges | CVSS3: 4.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39913 Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges | CVSS3: 4.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39913 Accidental logging of system root password in the migration log in all ... | CVSS3: 4.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39912 A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39912 A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39912 A potential DoS vulnerability was discovered in GitLab CE/EE starting ... | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39911 An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers | CVSS3: 1.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39911 An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers | CVSS3: 1.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39911 An improper access control flaw in all versions of GitLab CE/EE starti ... | CVSS3: 1.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39910 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature. | CVSS3: 2.6 | 0% Низкий | около 4 лет назад | |
CVE-2021-39910 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature. | CVSS3: 2.6 | 0% Низкий | около 4 лет назад | |
CVE-2021-39910 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 2.6 | 0% Низкий | около 4 лет назад | |
CVE-2021-39909 Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39909 Lack of email address ownership verification in the CODEOWNERS feature ... | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39908 In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
CVE-2021-39908 In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу