CVE-2020-13335
- EPSS 0.15%
- Veröffentlicht 07.10.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:03
Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.
CVE-2020-13346
- EPSS 0.13%
- Veröffentlicht 07.10.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:05
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
CVE-2020-13347
- EPSS 1.09%
- Veröffentlicht 07.10.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:05
A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows ho...
CVE-2020-13333
- EPSS 0.15%
- Veröffentlicht 06.10.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:03
A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in hig...
CVE-2020-13343
- EPSS 0.14%
- Veröffentlicht 06.10.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:04
An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template
CVE-2020-13345
- EPSS 0.2%
- Veröffentlicht 06.10.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:04
An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes
CVE-2020-13337
- EPSS 0.13%
- Veröffentlicht 02.10.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:03
An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.
CVE-2020-13338
- EPSS 0.09%
- Veröffentlicht 02.10.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:03
An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.
CVE-2020-13336
- EPSS 0.12%
- Veröffentlicht 30.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:03
An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.
CVE-2020-13331
- EPSS 0.12%
- Veröffentlicht 30.09.2020 18:15:20
- Zuletzt bearbeitet 21.11.2024 05:01:03
An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.