Search CVE reports


Toggle filters

941 – 950 of 1535 results


CVE-2021-22196

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-20291

Medium priority
Vulnerable

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this...

1 affected package

golang-github-containers-storage

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-storage Not affected Not affected Vulnerable Not in release
Show less packages

CVE-2021-22177

Medium priority
Ignored

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-29272

Medium priority
Vulnerable

bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string.

1 affected package

golang-github-microcosm-cc-bluemonday

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-microcosm-cc-bluemonday Not affected Vulnerable Not in release Vulnerable
Show less packages

CVE-2021-20206

Medium priority
Needs evaluation

An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements...

1 affected package

golang-github-appc-cni

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-appc-cni Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-22194

Medium priority
Not affected

In all versions of GitLab, marshalled session keys were being stored in Redis.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2021-22184

Medium priority
Not affected

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2021-22180

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-22172

Low priority
Ignored

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-22169

Low priority
Ignored

An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages