CVE-2021-22189
- EPSS 0.66%
- Veröffentlicht 04.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:40
Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.
CVE-2021-22182
- EPSS 1.01%
- Veröffentlicht 03.03.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:49:39
An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.
CVE-2021-22188
- EPSS 1.31%
- Veröffentlicht 03.03.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:49:40
An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.
CVE-2021-22187
- EPSS 1.04%
- Veröffentlicht 02.03.2021 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:49:40
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.
CVE-2021-22166
- EPSS 1.38%
- Veröffentlicht 15.01.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:37
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method
CVE-2021-22167
- EPSS 1.57%
- Veröffentlicht 15.01.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:37
An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository
CVE-2021-22168
- EPSS 1%
- Veröffentlicht 15.01.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:37
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
CVE-2021-22171
- EPSS 1.33%
- Veröffentlicht 15.01.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:38
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link
CVE-2020-26414
- EPSS 1.53%
- Veröffentlicht 15.01.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:53
An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.
CVE-2020-26411
- EPSS 1.2%
- Veröffentlicht 11.12.2020 05:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:52
A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to ...