CVE-2022-1999
- EPSS 0.2%
- Veröffentlicht 01.07.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:41:55
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.
CVE-2022-2228
- EPSS 0.21%
- Veröffentlicht 01.07.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:00:34
Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access res...
CVE-2022-2229
- EPSS 0.29%
- Veröffentlicht 01.07.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:00:35
An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public proje...
CVE-2022-2270
- EPSS 0.16%
- Veröffentlicht 01.07.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:00:39
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect pe...
CVE-2022-1983
- EPSS 0.13%
- Veröffentlicht 01.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:53
Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location t...
CVE-2022-2185
- EPSS 93.34%
- Veröffentlicht 01.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:30
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted pro...
CVE-2022-2227
- EPSS 0.16%
- Veröffentlicht 01.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:34
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta dat...
CVE-2022-2230
- EPSS 6.59%
- Veröffentlicht 01.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:35
A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in Git...
CVE-2022-2235
- EPSS 4.62%
- Veröffentlicht 01.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:35
Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously...
CVE-2022-2243
- EPSS 0.18%
- Veröffentlicht 01.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:36
An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.