Количество 5 545
Количество 5 545
CVE-2021-39884
In all versions of GitLab EE since version 8.13, an endpoint discloses ...
CVE-2021-39883
Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.
CVE-2021-39883
Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.
CVE-2021-39883
Improper authorization checks in all versions of GitLab EE starting fr ...
CVE-2021-39882
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
CVE-2021-39882
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
CVE-2021-39882
In all versions of GitLab CE/EE, provided a user ID, anonymous users c ...
CVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.
CVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.
CVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may ...
CVE-2021-39880
A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.
CVE-2021-39880
A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.
CVE-2021-39880
A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ...
CVE-2021-39879
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication
CVE-2021-39879
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication
CVE-2021-39879
Missing authentication in all versions of GitLab CE/EE since version 7 ...
CVE-2021-39878
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.
CVE-2021-39878
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.
CVE-2021-39878
A stored Reflected Cross-Site Scripting vulnerability in the Jira inte ...
CVE-2021-39877
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39884 In all versions of GitLab EE since version 8.13, an endpoint discloses ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39883 Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39883 Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39883 Improper authorization checks in all versions of GitLab EE starting fr ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39882 In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39882 In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39882 In all versions of GitLab CE/EE, provided a user ID, anonymous users c ... | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39881 In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description. | CVSS3: 3.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39881 In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description. | CVSS3: 3.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39881 In all versions of GitLab CE/EE since version 7.7, the application may ... | CVSS3: 3.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39880 A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39880 A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39880 A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ... | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39879 Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication | CVSS3: 2.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39879 Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication | CVSS3: 2.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39879 Missing authentication in all versions of GitLab CE/EE since version 7 ... | CVSS3: 2.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39878 A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code. | CVSS3: 5.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39878 A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code. | CVSS3: 5.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39878 A stored Reflected Cross-Site Scripting vulnerability in the Jira inte ... | CVSS3: 5.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39877 A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file. | CVSS3: 7.7 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу