Количество 5 545
Количество 5 545
CVE-2021-39911
An improper access control flaw in all versions of GitLab CE/EE starti ...
CVE-2021-39910
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.
CVE-2021-39910
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.
CVE-2021-39910
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2021-39909
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances
CVE-2021-39909
Lack of email address ownership verification in the CODEOWNERS feature ...
CVE-2021-39908
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.
CVE-2021-39908
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.
CVE-2021-39908
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all ...
CVE-2021-39907
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.
CVE-2021-39907
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.
CVE-2021-39907
A potential DOS vulnerability was discovered in GitLab CE/EE starting ...
CVE-2021-39906
Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVE-2021-39906
Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVE-2021-39906
Improper validation of ipynb files in GitLab CE/EE version 13.5 and ab ...
CVE-2021-39905
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with
CVE-2021-39905
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with
CVE-2021-39905
An information disclosure vulnerability in the GitLab CE/EE API since ...
CVE-2021-39904
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
CVE-2021-39904
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39911 An improper access control flaw in all versions of GitLab CE/EE starti ... | CVSS3: 1.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39910 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature. | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39910 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature. | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39910 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39909 Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39909 Lack of email address ownership verification in the CODEOWNERS feature ... | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39908 In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI. | CVSS3: 6.5 | 0% Низкий | около 4 лет назад | |
CVE-2021-39908 In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI. | CVSS3: 6.5 | 0% Низкий | около 4 лет назад | |
CVE-2021-39908 In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all ... | CVSS3: 6.5 | 0% Низкий | около 4 лет назад | |
CVE-2021-39907 A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39907 A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39907 A potential DOS vulnerability was discovered in GitLab CE/EE starting ... | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39906 Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf. | CVSS3: 8.7 | 1% Низкий | больше 4 лет назад | |
CVE-2021-39906 Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf. | CVSS3: 8.7 | 1% Низкий | больше 4 лет назад | |
CVE-2021-39906 Improper validation of ipynb files in GitLab CE/EE version 13.5 and ab ... | CVSS3: 8.7 | 1% Низкий | больше 4 лет назад | |
CVE-2021-39905 An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39905 An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39905 An information disclosure vulnerability in the GitLab CE/EE API since ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39904 An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39904 An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу