|
210441
|
8.7 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
|
CWE-79
Cross-site Scripting
|
CVE-2020-13340
|
2024-11-21 14:01 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210442
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited due to the current user only being impacted.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13339
|
2024-11-21 14:01 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210443
|
2.7 |
LOW
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-13342
|
2024-11-21 14:01 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210444
|
9.1 |
CRITICAL
Network
|
gitlab
|
gitlab
|
A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows t…
|
CWE-22
Path Traversal
|
CVE-2020-13347
|
2024-11-21 14:01 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210445
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
|
CWE-459
Incomplete Cleanup
|
CVE-2020-13346
|
2024-11-21 14:01 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210446
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.
|
CWE-863
Incorrect Authorization
|
CVE-2020-13335
|
2024-11-21 14:01 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210447
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query
|
CWE-863
Incorrect Authorization
|
CVE-2020-13334
|
2024-11-21 14:01 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210448
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes
|
CWE-79
Cross-site Scripting
|
CVE-2020-13345
|
2024-11-21 14:01 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210449
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-13343
|
2024-11-21 14:01 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210450
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtrack…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13333
|
2024-11-21 14:01 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|