Search CVE reports


Toggle filters

1171 – 1180 of 1670 results


CVE-2020-13321

Medium priority
Ignored

A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab — Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13320

Medium priority
Ignored

An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab — Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13319

Medium priority
Ignored

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab — Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13296

Medium priority
Ignored

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab — Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-15216

Medium priority
Needs evaluation

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is...

1 affected package

golang-github-russellhaering-goxmldsig

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-russellhaering-goxmldsig Not affected Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-25614

Medium priority
Vulnerable

xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.

1 affected package

golang-github-antchfx-xmlquery

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antchfx-xmlquery Not affected Not affected Not affected Vulnerable Not in release
Show less packages

CVE-2020-13308

Medium priority
Ignored

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor...

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab — Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13307

Medium priority
Ignored

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab — Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13303

Medium priority
Ignored

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab — Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13315

Medium priority
Ignored

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab — Not in release Not in release Not in release Not in release
Show less packages