Количество 5 336
Количество 5 336
CVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.
CVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may ...
CVE-2021-39880
A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.
CVE-2021-39880
A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.
CVE-2021-39880
A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ...
CVE-2021-39879
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication
CVE-2021-39879
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication
CVE-2021-39879
Missing authentication in all versions of GitLab CE/EE since version 7 ...
CVE-2021-39878
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.
CVE-2021-39878
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.
CVE-2021-39878
A stored Reflected Cross-Site Scripting vulnerability in the Jira inte ...
CVE-2021-39877
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
CVE-2021-39877
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
CVE-2021-39877
A vulnerability was discovered in GitLab starting with version 12.2 th ...
CVE-2021-39876
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.
CVE-2021-39876
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.
CVE-2021-39876
In all versions of GitLab CE/EE since version 11.3, the endpoint for a ...
CVE-2021-39875
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.
CVE-2021-39875
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.
CVE-2021-39875
In all versions of GitLab CE/EE since version 13.6, it is possible to ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39881 In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description. | CVSS3: 3.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39881 In all versions of GitLab CE/EE since version 7.7, the application may ... | CVSS3: 3.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39880 A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39880 A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39880 A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ... | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39879 Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication | CVSS3: 2.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39879 Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication | CVSS3: 2.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39879 Missing authentication in all versions of GitLab CE/EE since version 7 ... | CVSS3: 2.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39878 A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code. | CVSS3: 5.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39878 A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code. | CVSS3: 5.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39878 A stored Reflected Cross-Site Scripting vulnerability in the Jira inte ... | CVSS3: 5.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39877 A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file. | CVSS3: 7.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39877 A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file. | CVSS3: 7.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39877 A vulnerability was discovered in GitLab starting with version 12.2 th ... | CVSS3: 7.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39876 In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2021-39876 In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2021-39876 In all versions of GitLab CE/EE since version 11.3, the endpoint for a ... | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2021-39875 In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39875 In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39875 In all versions of GitLab CE/EE since version 13.6, it is possible to ... | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу