Search CVE reports


Toggle filters

1441 – 1450 of 1538 results


CVE-2018-16049

Medium priority
Ignored

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-16048

Low priority
Not affected

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2013-7203

Medium priority

Not in release

gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.

1 affected package

gitolite3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitolite3
Show less packages

CVE-2013-4451

Medium priority
Not affected

gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on...

2 affected packages

gitolite, gitolite3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitolite
gitolite3
Show less packages

CVE-2018-16976

Medium priority
Needs evaluation

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed....

2 affected packages

gitolite3, gitolite

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitolite3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gitolite Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-14632

Medium priority
Needs evaluation

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift...

1 affected package

golang-github-evanphx-json-patch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-evanphx-json-patch Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-15501

Medium priority
Vulnerable

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-14912

Medium priority

Some fixes available 1 of 2

cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.

1 affected package

cgit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cgit Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-12607

Medium priority
Ignored

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2018-12606

Medium priority
Ignored

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages