Количество 5 336
Количество 5 336
CVE-2021-39888
In all versions of GitLab EE starting from 13.10 before 14.1.7, all ve ...
CVE-2021-39887
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVE-2021-39887
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVE-2021-39887
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Mar ...
CVE-2021-39886
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.
CVE-2021-39886
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.
CVE-2021-39886
Permissions rules were not applied while issues were moved between pro ...
CVE-2021-39885
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names
CVE-2021-39885
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names
CVE-2021-39885
A Stored XSS in merge request creation page in all versions of Gitlab ...
CVE-2021-39884
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
CVE-2021-39884
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
CVE-2021-39884
In all versions of GitLab EE since version 8.13, an endpoint discloses ...
CVE-2021-39883
Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.
CVE-2021-39883
Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.
CVE-2021-39883
Improper authorization checks in all versions of GitLab EE starting fr ...
CVE-2021-39882
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
CVE-2021-39882
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
CVE-2021-39882
In all versions of GitLab CE/EE, provided a user ID, anonymous users c ...
CVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39888 In all versions of GitLab EE starting from 13.10 before 14.1.7, all ve ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39887 A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf. | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39887 A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf. | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39887 A stored Cross-Site Scripting vulnerability in the GitLab Flavored Mar ... | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39886 Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references. | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39886 Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references. | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39886 Permissions rules were not applied while issues were moved between pro ... | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39885 A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39885 A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39885 A Stored XSS in merge request creation page in all versions of Gitlab ... | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39884 In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39884 In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39884 In all versions of GitLab EE since version 8.13, an endpoint discloses ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39883 Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39883 Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39883 Improper authorization checks in all versions of GitLab EE starting fr ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39882 In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39882 In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39882 In all versions of GitLab CE/EE, provided a user ID, anonymous users c ... | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39881 In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description. | CVSS3: 3.5 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу