Количество 5 336
Количество 5 336
CVE-2019-5883
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.
CVE-2019-5883
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.
CVE-2019-5883
An Incorrect Access Control issue was discovered in GitLab Community a ...
CVE-2019-5487
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
CVE-2019-5487
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
CVE-2019-5487
An improper access control vulnerability exists in Gitlab EE <v12.3.3, ...
CVE-2019-5486
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
CVE-2019-5486
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
CVE-2019-5486
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, ...
CVE-2019-5474
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
CVE-2019-5474
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
CVE-2019-5474
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, ...
CVE-2019-5473
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.
CVE-2019-5473
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.
CVE-2019-5473
An authentication issue was discovered in GitLab that allowed a bypass ...
CVE-2019-5472
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
CVE-2019-5472
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
CVE-2019-5472
An authorization issue was discovered in Gitlab versions < 12.1.2, < 1 ...
CVE-2019-5471
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.
CVE-2019-5471
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-5883 An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to. | CVSS3: 9.1 | 0% Низкий | больше 6 лет назад | |
CVE-2019-5883 An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to. | CVSS3: 9.1 | 0% Низкий | больше 6 лет назад | |
CVE-2019-5883 An Incorrect Access Control issue was discovered in GitLab Community a ... | CVSS3: 9.1 | 0% Низкий | больше 6 лет назад | |
CVE-2019-5487 An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits. | CVSS3: 5.3 | 0% Низкий | около 6 лет назад | |
CVE-2019-5487 An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits. | CVSS3: 5.3 | 0% Низкий | около 6 лет назад | |
CVE-2019-5487 An improper access control vulnerability exists in Gitlab EE <v12.3.3, ... | CVSS3: 5.3 | 0% Низкий | около 6 лет назад | |
CVE-2019-5486 A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements. | CVSS3: 8.8 | 0% Низкий | около 6 лет назад | |
CVE-2019-5486 A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements. | CVSS3: 8.8 | 0% Низкий | около 6 лет назад | |
CVE-2019-5486 A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, ... | CVSS3: 8.8 | 0% Низкий | около 6 лет назад | |
CVE-2019-5474 An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. | CVSS3: 6.5 | 0% Низкий | около 6 лет назад | |
CVE-2019-5474 An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. | CVSS3: 6.5 | 0% Низкий | около 6 лет назад | |
CVE-2019-5474 An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, ... | CVSS3: 6.5 | 0% Низкий | около 6 лет назад | |
CVE-2019-5473 An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4. | CVSS3: 7.2 | 0% Низкий | больше 6 лет назад | |
CVE-2019-5473 An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4. | CVSS3: 7.2 | 0% Низкий | больше 6 лет назад | |
CVE-2019-5473 An authentication issue was discovered in GitLab that allowed a bypass ... | CVSS3: 7.2 | 0% Низкий | больше 6 лет назад | |
CVE-2019-5472 An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments. | CVSS3: 7.5 | 0% Низкий | около 6 лет назад | |
CVE-2019-5472 An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments. | CVSS3: 7.5 | 0% Низкий | около 6 лет назад | |
CVE-2019-5472 An authorization issue was discovered in Gitlab versions < 12.1.2, < 1 ... | CVSS3: 7.5 | 0% Низкий | около 6 лет назад | |
CVE-2019-5471 An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6. | CVSS3: 5.4 | 0% Низкий | больше 6 лет назад | |
CVE-2019-5471 An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6. | CVSS3: 5.4 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу