Search CVE reports


Toggle filters

1171 – 1180 of 1538 results


CVE-2019-15594

Medium priority
Not affected

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2019-15592

Medium priority
Ignored

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-8945

Medium priority
Vulnerable

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

2 affected packages

golang-github-proglottis-gpgme, singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-proglottis-gpgme Not affected Not affected Vulnerable Not in release
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2020-6833

Medium priority
Not affected

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7978

Medium priority
Not affected

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7977

Medium priority
Not affected

GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7976

Medium priority
Not affected

GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7974

Medium priority
Not affected

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7973

Medium priority
Not affected

GitLab through 12.7.2 allows XSS.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7972

Medium priority
Not affected

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages