CVE-2021-39882
- EPSS 0.1%
- Veröffentlicht 05.10.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:27
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
CVE-2021-39884
- EPSS 0.27%
- Veröffentlicht 05.10.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:28
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
CVE-2021-39888
- EPSS 0.26%
- Veröffentlicht 05.10.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:28
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info...
CVE-2021-39893
- EPSS 0.4%
- Veröffentlicht 05.10.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:29
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
CVE-2021-39894
- EPSS 0.17%
- Veröffentlicht 05.10.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:29
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.
CVE-2021-39866
- EPSS 0.26%
- Veröffentlicht 05.10.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:20:25
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVE-2021-39867
- EPSS 0.15%
- Veröffentlicht 05.10.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:20:25
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVE-2021-39887
- EPSS 0.2%
- Veröffentlicht 05.10.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:20:28
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVE-2021-39874
- EPSS 0.25%
- Veröffentlicht 04.10.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:26
In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.
CVE-2021-39877
- EPSS 0.18%
- Veröffentlicht 04.10.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:26
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.