Search CVE reports


Toggle filters

1391 – 1400 of 1538 results


CVE-2019-11000

Low priority
Not affected

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2019-3564

Medium priority
Needs evaluation

Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to...

2 affected packages

thrift, golang-github-uber-go-tally

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thrift Not affected Not affected Not affected Not in release
golang-github-uber-go-tally Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2019-11576

Medium priority
Needs evaluation

Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.

1 affected package

golang-code.gitea-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-code.gitea-git Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-19359

Medium priority
Not affected

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2018-18643

Medium priority
Not affected

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2017-18367

Medium priority

Some fixes available 1 of 4

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass...

1 affected package

golang-github-seccomp-libseccomp-golang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-seccomp-libseccomp-golang Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-9890

Low priority
Not affected

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2019-9756

Low priority
Ignored

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9225

Low priority
Not affected

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 5 of 5).

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2019-9224

Low priority
Not affected

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 4 of 5).

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages