CVE-2022-1413
- EPSS 0.21%
- Veröffentlicht 19.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:40
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed i...
CVE-2022-1416
- EPSS 0.23%
- Veröffentlicht 19.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:41
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker co...
CVE-2022-1423
- EPSS 0.1%
- Veröffentlicht 19.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:42
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Develope...
CVE-2022-1433
- EPSS 0.23%
- Veröffentlicht 11.05.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:43
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential ...
CVE-2022-1460
- EPSS 0.28%
- Veröffentlicht 11.05.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:45
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on schedul...
CVE-2022-1510
- EPSS 0.23%
- Veröffentlicht 11.05.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:52
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI...
CVE-2022-1545
- EPSS 0.26%
- Veröffentlicht 11.05.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:56
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.
CVE-2022-1124
- EPSS 0.25%
- Veröffentlicht 11.05.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:05
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
CVE-2022-1352
- EPSS 0.22%
- Veröffentlicht 11.05.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:33
Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with...
CVE-2022-1406
- EPSS 0.22%
- Veröffentlicht 11.05.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:40
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project