Количество 5 545
Количество 5 545
CVE-2021-39890
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
CVE-2021-39890
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
CVE-2021-39890
It was possible to bypass 2FA for LDAP users and access some specific ...
CVE-2021-39889
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.
CVE-2021-39889
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.
CVE-2021-39889
In all versions of GitLab EE since version 14.1, due to an insecure di ...
CVE-2021-39888
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.
CVE-2021-39888
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.
CVE-2021-39888
In all versions of GitLab EE starting from 13.10 before 14.1.7, all ve ...
CVE-2021-39887
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVE-2021-39887
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVE-2021-39887
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Mar ...
CVE-2021-39886
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.
CVE-2021-39886
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.
CVE-2021-39886
Permissions rules were not applied while issues were moved between pro ...
CVE-2021-39885
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names
CVE-2021-39885
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names
CVE-2021-39885
A Stored XSS in merge request creation page in all versions of Gitlab ...
CVE-2021-39884
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
CVE-2021-39884
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39890 It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above. | CVSS3: 3.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39890 It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above. | CVSS3: 3.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39890 It was possible to bypass 2FA for LDAP users and access some specific ... | CVSS3: 3.1 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39889 In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39889 In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39889 In all versions of GitLab EE since version 14.1, due to an insecure di ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39888 In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39888 In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39888 In all versions of GitLab EE starting from 13.10 before 14.1.7, all ve ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39887 A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf. | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39887 A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf. | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39887 A stored Cross-Site Scripting vulnerability in the GitLab Flavored Mar ... | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39886 Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references. | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39886 Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references. | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39886 Permissions rules were not applied while issues were moved between pro ... | CVSS3: 2.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39885 A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39885 A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39885 A Stored XSS in merge request creation page in all versions of Gitlab ... | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39884 In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39884 In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу