Search CVE reports


Toggle filters

651 – 660 of 1533 results


CVE-2022-2865

Medium priority
Ignored

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-2630

Medium priority
Ignored

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-2592

Medium priority
Ignored

A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-2533

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-2527

Medium priority
Ignored

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-2455

Medium priority
Ignored

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-2428

Medium priority
Ignored

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-42906

Medium priority
Needs evaluation

powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When...

1 affected package

powerline-gitstatus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
powerline-gitstatus Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-39237

Medium priority
Vulnerable

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure...

2 affected packages

golang-github-sylabs-sif, singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sylabs-sif Not affected Vulnerable Vulnerable Not in release
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40083

Medium priority
Needs evaluation

Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).

4 affected packages

golang-github-labstack-echo, golang-github-labstack-echo.v2, golang-github-labstack-echo.v3, golang-github-labstack-gommon

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-labstack-echo Needs evaluation Needs evaluation Not in release Not in release
golang-github-labstack-echo.v2 Not in release Needs evaluation Needs evaluation Not in release
golang-github-labstack-echo.v3 Not in release Needs evaluation Needs evaluation Not in release
golang-github-labstack-gommon Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages