|
210231
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.
|
NVD-CWE-noinfo
|
CVE-2020-10981
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210232
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-10980
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210233
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.
|
NVD-CWE-noinfo
|
CVE-2020-10979
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210234
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.
|
NVD-CWE-noinfo
|
CVE-2020-10978
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210235
|
8.8 |
HIGH
Network
|
dropwizard
|
dropwizard_validation
|
dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to …
|
CWE-74
Injection
|
CVE-2020-11002
|
2024-11-21 13:56 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210236
|
5.5 |
MEDIUM
Local
|
gitlab
|
gitlab
|
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
|
CWE-22
Path Traversal
|
CVE-2020-10977
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210237
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.
|
CWE-200
Information Exposure
|
CVE-2020-10976
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210238
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.
|
NVD-CWE-noinfo
|
CVE-2020-10975
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210239
|
5.5 |
MEDIUM
Local
|
codeblocks
|
code\
|
A buffer overflow vulnerability in Code::Blocks 17.12 allows an attacker to execute arbitrary code via a crafted project file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10814
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210240
|
6.5 |
MEDIUM
Network
|
greenbrowser_project
|
greenbrowser
|
GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL p…
|
NVD-CWE-Other
|
CVE-2020-11000
|
2024-11-21 13:56 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|