Search CVE reports


Toggle filters

1001 – 1010 of 1533 results


CVE-2020-13354

Low priority
Not affected

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage....

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2020-13353

Low priority

Not in release

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.

1 affected package

gitaly

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitaly Not in release Not in release
Show less packages

CVE-2020-13352

Low priority
Not affected

Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2020-26892

Medium priority
Needs evaluation

The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.

1 affected package

golang-github-nats-io-jwt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-nats-io-jwt Not affected Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-26521

Medium priority
Needs evaluation

The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).

1 affected package

golang-github-nats-io-jwt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-nats-io-jwt Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-27955

Medium priority
Not affected

Git LFS 2.12.0 allows Remote Code Execution.

1 affected package

git-lfs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git-lfs Not affected Not affected
Show less packages

CVE-2020-13327

Medium priority
Needs evaluation

An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner...

1 affected package

gitlab-ci-multi-runner

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab-ci-multi-runner Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2020-13341

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform various deletions.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13344

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13340

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages