Search CVE reports


Toggle filters

901 – 910 of 1538 results


CVE-2021-22238

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-38711

Medium priority
Needs evaluation

In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.

1 affected package

gitit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitit Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-22234

Medium priority
Needs evaluation

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
gitlab-agent Needs evaluation Not in release Not in release
Show less packages

CVE-2021-22241

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2021-23409

Medium priority
Vulnerable

The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.

1 affected package

golang-github-pires-go-proxyproto

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-pires-go-proxyproto Not affected Vulnerable Not in release Not in release
Show less packages

CVE-2021-22233

Medium priority
Ignored

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-22225

Medium priority
Ignored

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-22224

Medium priority
Ignored

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-22231

Medium priority
Ignored

A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-22230

Medium priority
Ignored

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages