Search CVE reports


Toggle filters

1341 – 1350 of 1538 results


CVE-2019-14943

Medium priority
Not affected

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2019-1020014

Low priority
Fixed

docker-credential-helpers before 0.6.3 has a double free in the List functions.

2 affected packages

golang-github-docker-docker-credential-helpers, docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-docker-docker-credential-helpers Not affected Not affected Fixed
docker.io Not affected Not affected Fixed
Show less packages

CVE-2019-1010261

Medium priority
Needs evaluation

Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to...

1 affected package

golang-code.gitea-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-code.gitea-git Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-1010314

Medium priority
Needs evaluation

Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is:...

1 affected package

golang-code.gitea-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-code.gitea-git Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-19584

Medium priority
Not affected

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2018-19583

Medium priority
Ignored

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-19582

Low priority
Not affected

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2018-19581

Low priority
Not affected

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2018-19580

Low priority
Ignored

All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-19579

Low priority
Not affected

GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages