Search CVE reports


Toggle filters

1181 – 1190 of 1547 results


CVE-2019-15592

Medium priority
Ignored

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-8945

Medium priority
Vulnerable

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

2 affected packages

golang-github-proglottis-gpgme, singularity-container

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-proglottis-gpgme Not affected Not affected Not affected Vulnerable Not in release
singularity-container Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2020-6833

Medium priority
Not affected

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7978

Medium priority
Not affected

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7977

Medium priority
Not affected

GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7976

Medium priority
Not affected

GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7974

Medium priority
Not affected

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7973

Medium priority
Not affected

GitLab through 12.7.2 allows XSS.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7972

Medium priority
Not affected

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2020-7971

Medium priority
Not affected

GitLab EE 11.0 and later through 12.7.2 allows XSS.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages