CVE-2021-22246
- EPSS 0.22%
- Veröffentlicht 20.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:47
A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.
CVE-2021-22254
- EPSS 0.27%
- Veröffentlicht 20.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:48
Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.
CVE-2021-22234
- EPSS 0.17%
- Veröffentlicht 05.08.2021 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:49:45
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attac...
CVE-2021-22240
- EPSS 0.23%
- Veröffentlicht 05.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:46
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled
CVE-2021-22241
- EPSS 0.19%
- Veröffentlicht 05.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:46
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.
CVE-2021-22233
- EPSS 0.19%
- Veröffentlicht 07.07.2021 14:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:45
An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details
CVE-2021-22224
- EPSS 0.37%
- Veröffentlicht 07.07.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:44
A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim
CVE-2021-22225
- EPSS 0.14%
- Veröffentlicht 07.07.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:44
Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown
CVE-2021-22227
- EPSS 0.11%
- Veröffentlicht 07.07.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:45
A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it
CVE-2021-22230
- EPSS 0.2%
- Veröffentlicht 07.07.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:45
Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.