Количество 5 336
Количество 5 336
CVE-2021-39868
In all versions of GitLab CE/EE since version 8.12, an authenticated l ...
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ...
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 ...
CVE-2021-22264
An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.
CVE-2021-22264
An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.
CVE-2021-22264
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2021-22263
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.
CVE-2021-22263
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.
CVE-2021-22263
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2021-22262
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page
CVE-2021-22262
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page
CVE-2021-22262
Missing access control in all GitLab versions starting from 13.12 befo ...
CVE-2021-22261
A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses
CVE-2021-22261
A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses
CVE-2021-22261
A stored Cross-Site Scripting vulnerability in the Jira integration in ...
CVE-2021-22260
A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39868 In all versions of GitLab CE/EE since version 8.12, an authenticated l ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ... | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens. | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens. | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 ... | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22264 An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted. | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22264 An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted. | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22264 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22263 An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22263 An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22263 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22262 Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22262 Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22262 Missing access control in all GitLab versions starting from 13.12 befo ... | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22261 A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22261 A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22261 A stored Cross-Site Scripting vulnerability in the Jira integration in ... | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22260 A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf | CVSS3: 7.7 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу