Gitlab

GitLab

1271 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 14.09.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:00

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

  • EPSS 0.16%
  • Veröffentlicht 14.09.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:00

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.

  • EPSS 0.28%
  • Veröffentlicht 14.09.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:00

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to the user within error messages.

  • EPSS 0.21%
  • Veröffentlicht 14.09.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:01

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.

  • EPSS 0.31%
  • Veröffentlicht 14.09.2020 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:01

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

  • EPSS 0.13%
  • Veröffentlicht 14.09.2020 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:01

A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

  • EPSS 0.15%
  • Veröffentlicht 14.09.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:56

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

  • EPSS 0.27%
  • Veröffentlicht 14.09.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:57

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

  • EPSS 0.17%
  • Veröffentlicht 14.09.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:57

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

  • EPSS 0.19%
  • Veröffentlicht 14.09.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:58

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.