Search CVE reports


Toggle filters

411 – 420 of 1520 results


CVE-2023-3443

Medium priority
Not affected

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not affected
Show less packages

CVE-2023-45286

Medium priority
Needs evaluation

A race condition in go-resty can result in HTTP request body disclosure across requests. This condition can be triggered by calling sync.Pool.Put with the same *bytes.Buffer more than once, when request retries are enabled and a...

1 affected package

golang-github-go-resty-resty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-resty-resty Needs evaluation Needs evaluation Not in release Ignored
Show less packages

CVE-2023-3909

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2023-3399

Medium priority
Needs evaluation

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2023-3246

Medium priority
Needs evaluation

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2023-5831

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2023-5825

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2023-46239

Medium priority
Needs evaluation

quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could...

1 affected package

golang-github-lucas-clemente-quic-go

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-lucas-clemente-quic-go Needs evaluation Needs evaluation Not in release Ignored
Show less packages

CVE-2023-46129

Medium priority
Vulnerable

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support...

2 affected packages

golang-github-nats-io-nkeys, nats-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-nats-io-nkeys Not affected Vulnerable Vulnerable Ignored
nats-server Not affected Not in release Not in release Ignored
Show less packages

CVE-2023-45683

Medium priority
Vulnerable

github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register...

1 affected package

golang-github-crewjam-saml

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-crewjam-saml Vulnerable Vulnerable Not in release Not in release
Show less packages