Search CVE reports


Toggle filters

61 – 70 of 1278 results


CVE-2024-6595

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gitlab Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-5528

Medium priority
Needs evaluation

[Unknown description]

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gitlab Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-6385

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gitlab Not in release Not in release Not in release Needs evaluation
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2024-5470

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gitlab Not in release Not in release Not in release Needs evaluation
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2024-5257

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gitlab Not in release Not in release Not in release Needs evaluation
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2024-2880

Medium priority
Needs evaluation

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gitlab Not in release Not in release Not in release Needs evaluation
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2024-2177

Medium priority
Ignored

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gitlab Not in release Not in release Not in release Ignored
Show less packages

CVE-2024-6284

Medium priority
Needs evaluation

In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue...

1 affected package

golang-github-google-nftables

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
golang-github-google-nftables Needs evaluation Not in release Not in release
Show less packages

CVE-2024-37298

Medium priority
Needs evaluation

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations,...

1 affected package

golang-github-gorilla-schema

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
golang-github-gorilla-schema Needs evaluation Not in release Not in release
Show less packages

CVE-2019-25211

Medium priority
Needs evaluation

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should...

1 affected package

golang-github-gin-contrib-cors

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
golang-github-gin-contrib-cors Needs evaluation Needs evaluation Needs evaluation
Show less packages