Search CVE reports


Toggle filters

1091 – 1100 of 1533 results


CVE-2020-13277

Medium priority
Not affected

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2020-13271

Medium priority
Ignored

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-13270

Medium priority
Ignored

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-11091

Medium priority

Not in release

In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a cluster with an IPv4 internal...

1 affected package

golang-github-weaveworks-mesh-dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-weaveworks-mesh-dev Not in release Not in release
Show less packages

CVE-2020-10749

Medium priority
Needs evaluation

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit...

1 affected package

golang-github-containernetworking-plugins

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containernetworking-plugins Not affected Not affected Needs evaluation Not in release
Show less packages

CVE-2020-12448

Negligible priority
Not affected

GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2020-12277

Medium priority
Ignored

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-12276

Medium priority
Ignored

GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-12275

Medium priority
Ignored

GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-12279

Medium priority

Some fixes available 2 of 8

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue...

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Fixed
Show less packages