Количество 5 545
Количество 5 545
CVE-2021-22242
Insufficient input sanitization in Mermaid markdown in GitLab CE/EE ve ...
CVE-2021-22241
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.
CVE-2021-22241
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.
CVE-2021-22241
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2021-22240
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled
CVE-2021-22240
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14 ...
CVE-2021-22239
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
CVE-2021-22239
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
CVE-2021-22239
An unauthorized user was able to insert metadata when creating new iss ...
CVE-2021-22238
An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.
CVE-2021-22238
An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.
CVE-2021-22238
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2021-22237
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2
CVE-2021-22237
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2
CVE-2021-22237
Under specialized conditions, GitLab may allow a user with an imperson ...
CVE-2021-22236
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.
CVE-2021-22236
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.
CVE-2021-22236
Due to improper handling of OAuth client IDs, new subscriptions genera ...
CVE-2021-22234
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.
CVE-2021-22234
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-22242 Insufficient input sanitization in Mermaid markdown in GitLab CE/EE ve ... | CVSS3: 8.7 | 2% Низкий | больше 4 лет назад | |
CVE-2021-22241 An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name. | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22241 An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name. | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22241 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 8.7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22240 Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled | CVSS3: 4.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22240 Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14 ... | CVSS3: 4.2 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22239 An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later. | CVSS3: 5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22239 An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later. | CVSS3: 5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22239 An unauthorized user was able to insert metadata when creating new iss ... | CVSS3: 5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22238 An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues. | CVSS3: 6.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-22238 An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues. | CVSS3: 6.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-22238 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 6.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-22237 Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2 | CVSS3: 6.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22237 Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2 | CVSS3: 6.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22237 Under specialized conditions, GitLab may allow a user with an imperson ... | CVSS3: 6.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22236 Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22236 Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22236 Due to improper handling of OAuth client IDs, new subscriptions genera ... | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22234 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server. | CVSS3: 9.6 | 0% Низкий | больше 4 лет назад | |
CVE-2021-22234 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server. | CVSS3: 9.6 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу