Количество 5 943
Количество 5 943
CVE-2019-12825
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.
CVE-2019-12825
Unauthorized Access to the Container Registry of other groups was disc ...
CVE-2019-12446
An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.
CVE-2019-12446
An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.
CVE-2019-12446
An issue was discovered in GitLab Community and Enterprise Edition 8.3 ...
CVE-2019-12445
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.
CVE-2019-12445
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.
CVE-2019-12445
An issue was discovered in GitLab Community and Enterprise Edition 8.4 ...
CVE-2019-12444
An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.
CVE-2019-12444
An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.
CVE-2019-12444
An issue was discovered in GitLab Community and Enterprise Edition 8.9 ...
CVE-2019-12443
An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.
CVE-2019-12443
An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.
CVE-2019-12443
An issue was discovered in GitLab Community and Enterprise Edition 10. ...
CVE-2019-12442
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.
CVE-2019-12442
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.
CVE-2019-12442
An issue was discovered in GitLab Enterprise Edition 11.7 through 11.1 ...
CVE-2019-12441
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.
CVE-2019-12441
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.
CVE-2019-12441
An issue was discovered in GitLab Community and Enterprise Edition 8.4 ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-12825 Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12825 Unauthorized Access to the Container Registry of other groups was disc ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12446 An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12446 An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12446 An issue was discovered in GitLab Community and Enterprise Edition 8.3 ... | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12445 An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS. | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12445 An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS. | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12445 An issue was discovered in GitLab Community and Enterprise Edition 8.4 ... | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12444 An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12444 An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12444 An issue was discovered in GitLab Community and Enterprise Edition 8.9 ... | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12443 An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks. | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12443 An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks. | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12443 An issue was discovered in GitLab Community and Enterprise Edition 10. ... | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12442 An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12442 An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12442 An issue was discovered in GitLab Enterprise Edition 11.7 through 11.1 ... | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12441 An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12441 An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2019-12441 An issue was discovered in GitLab Community and Enterprise Edition 8.4 ... | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу