Количество 5 545
Количество 5 545
CVE-2021-39870
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.
CVE-2021-39870
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.
CVE-2021-39870
In all versions of GitLab CE/EE since version 11.11, an instance that ...
CVE-2021-39869
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
CVE-2021-39869
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
CVE-2021-39869
In all versions of GitLab CE/EE since version 8.9, project exports may ...
CVE-2021-39868
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.
CVE-2021-39868
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.
CVE-2021-39868
In all versions of GitLab CE/EE since version 8.12, an authenticated l ...
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ...
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 ...
CVE-2021-22264
An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.
CVE-2021-22264
An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.
CVE-2021-22264
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2021-22263
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.
CVE-2021-22263
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39870 In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39870 In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39870 In all versions of GitLab CE/EE since version 11.11, an instance that ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39869 In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39869 In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39869 In all versions of GitLab CE/EE since version 8.9, project exports may ... | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39868 In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39868 In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export. | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39868 In all versions of GitLab CE/EE since version 8.12, an authenticated l ... | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39867 In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ... | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens. | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens. | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39866 A business logic error in the project deletion process in GitLab 13.6 ... | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22264 An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted. | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22264 An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted. | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22264 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22263 An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22263 An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу