Количество 5 336
Количество 5 336
CVE-2021-22224
A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim
CVE-2021-22224
A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim
CVE-2021-22224
A cross-site request forgery vulnerability in the GraphQL API in GitLa ...
CVE-2021-22223
Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link
CVE-2021-22223
Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link
CVE-2021-22223
Client-Side code injection through Feature Flag name in GitLab CE/EE s ...
CVE-2021-22221
An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired
CVE-2021-22221
An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired
CVE-2021-22221
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2021-22220
An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.
CVE-2021-22220
An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.
CVE-2021-22220
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2021-22219
All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
CVE-2021-22219
All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
CVE-2021-22219
All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all ver ...
CVE-2021-22218
All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.
CVE-2021-22218
All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.
CVE-2021-22218
All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all ve ...
CVE-2021-22217
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request
CVE-2021-22217
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-22224 A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim | CVSS3: 7.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22224 A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim | CVSS3: 7.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22224 A cross-site request forgery vulnerability in the GraphQL API in GitLa ... | CVSS3: 7.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22223 Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22223 Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22223 Client-Side code injection through Feature Flag name in GitLab CE/EE s ... | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22221 An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22221 An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22221 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22220 An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks. | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22220 An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks. | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22220 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22219 All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking. | CVSS3: 4.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22219 All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking. | CVSS3: 4.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22219 All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all ver ... | CVSS3: 4.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22218 All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits. | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22218 All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits. | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22218 All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all ve ... | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22217 A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2021-22217 A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу