|
209571
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13331
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209572
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13330
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209573
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13329
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209574
|
4.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13328
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209575
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.
|
NVD-CWE-noinfo
|
CVE-2020-13326
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209576
|
7.1 |
HIGH
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.
|
NVD-CWE-noinfo
|
CVE-2020-13325
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209577
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.
|
NVD-CWE-noinfo
|
CVE-2020-13324
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209578
|
7.7 |
HIGH
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos
|
NVD-CWE-noinfo
|
CVE-2020-13323
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209579
|
7.2 |
HIGH
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.
|
CWE-863
Incorrect Authorization
|
CVE-2020-13322
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209580
|
8.3 |
HIGH
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.
|
NVD-CWE-noinfo
|
CVE-2020-13321
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|