CVE-2022-1680
- EPSS 15.47%
- Veröffentlicht 06.06.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:14
An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, th...
- EPSS 0.97%
- Veröffentlicht 06.06.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:27
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers t...
CVE-2022-1821
- EPSS 0.83%
- Veröffentlicht 06.06.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:32
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access t...
CVE-2022-1935
- EPSS 0.66%
- Veröffentlicht 06.06.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:47
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger T...
CVE-2022-1936
- EPSS 0.66%
- Veröffentlicht 06.06.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:47
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy To...
CVE-2022-1940
- EPSS 6.47%
- Veröffentlicht 06.06.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:47
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a vi...
CVE-2022-1944
- EPSS 0.53%
- Veröffentlicht 06.06.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:48
When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open ter...
CVE-2022-1413
- EPSS 0.91%
- Veröffentlicht 19.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:40
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed i...
CVE-2022-1416
- EPSS 0.74%
- Veröffentlicht 19.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:41
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker co...
CVE-2022-1423
- EPSS 1.45%
- Veröffentlicht 19.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:42
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Develope...