Search CVE reports


Toggle filters

731 – 740 of 1535 results


CVE-2022-1417

Medium priority

Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab
Show less packages

CVE-2022-29173

Medium priority
Not affected

go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, checks for rollback attacks are...

1 affected package

golang-github-endophage-gotuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-endophage-gotuf Not in release Not in release Not affected
Show less packages

CVE-2021-41959

Medium priority
Vulnerable

JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/ecma-regexp-object.c after RegExp, which causes a memory leak.

2 affected packages

git, iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git Not affected Not affected Not affected Not affected
iotjs Not in release Vulnerable Not affected
Show less packages

CVE-2022-1227

Medium priority
Needs evaluation

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs...

1 affected package

golang-github-containers-psgo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-psgo Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-0477

Low priority

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab
Show less packages

CVE-2022-29583

Medium priority
Ignored

service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by...

2 affected packages

golang-github-kardianos-service, google-guest-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-kardianos-service Not affected Not affected Not in release
google-guest-agent Not affected Not affected Not affected
Show less packages

CVE-2022-25648

Medium priority
Needs evaluation

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that...

1 affected package

ruby-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-git Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-24765

Medium priority
Fixed

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could...

1 affected package

git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git Fixed Fixed Fixed
Show less packages

CVE-2022-1193

Medium priority
Ignored

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-1157

Medium priority
Ignored

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages