Количество 5 336
Количество 5 336
CVE-2020-13304
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.
CVE-2020-13304
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.
CVE-2020-13304
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...
CVE-2020-13303
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.
CVE-2020-13303
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.
CVE-2020-13303
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...
CVE-2020-13302
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.
CVE-2020-13302
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.
CVE-2020-13302
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...
CVE-2020-13301
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.
CVE-2020-13301
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.
CVE-2020-13301
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...
CVE-2020-13300
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
CVE-2020-13300
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
CVE-2020-13300
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth a ...
CVE-2020-13299
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.
CVE-2020-13299
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.
CVE-2020-13299
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ...
CVE-2020-13298
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.
CVE-2020-13298
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-13304 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions. | CVSS3: 3.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13304 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions. | CVSS3: 3.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13304 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ... | CVSS3: 3.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13303 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project. | CVSS3: 7.1 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13303 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project. | CVSS3: 7.1 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13303 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ... | CVSS3: 7.1 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13302 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password. | CVSS3: 3.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13302 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password. | CVSS3: 3.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13302 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ... | CVSS3: 3.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13301 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page. | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13301 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page. | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13301 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ... | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13300 GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow. | CVSS3: 8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13300 GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow. | CVSS3: 8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13300 GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth a ... | CVSS3: 8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13299 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session. | CVSS3: 8.1 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13299 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session. | CVSS3: 8.1 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13299 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2 ... | CVSS3: 8.1 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13298 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure. | CVSS3: 7.2 | 0% Низкий | больше 5 лет назад | |
CVE-2020-13298 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure. | CVSS3: 7.2 | 0% Низкий | больше 5 лет назад |
Уязвимостей на страницу