Search CVE reports


Toggle filters

1281 – 1290 of 1533 results


CVE-2019-18460

Medium priority
Not affected

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2019-10214

Medium priority
Needs evaluation

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry...

2 affected packages

golang-github-containers-image, singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-image Needs evaluation Needs evaluation Needs evaluation Not in release
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2019-15593

Medium priority
Not affected

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2013-1425

Medium priority
Not affected

ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.

1 affected package

ldap-git-backup

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldap-git-backup
Show less packages

CVE-2010-2447

Low priority
Not affected

gitolite before 1.4.1 does not filter src/ or hooks/ from path names.

1 affected package

gitolite

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitolite
Show less packages

CVE-2011-2186

Low priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

1 affected package

git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git
Show less packages

CVE-2019-15729

Medium priority
Not affected

An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2019-15740

Medium priority
Ignored

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-15739

Medium priority
Ignored

An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-15738

Medium priority
Not affected

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages