|
210801
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13285
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210802
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13283
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210803
|
3.5 |
LOW
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-13282
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210804
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13280
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210805
|
7.5 |
HIGH
Network
|
dovecot debian canonical fedoraproject
|
dovecot debian_linux ubuntu_linux fedora
|
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12674
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210806
|
7.5 |
HIGH
Network
|
dovecot debian canonical fedoraproject
|
dovecot debian_linux ubuntu_linux fedora
|
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12673
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210807
|
8.1 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
|
NVD-CWE-noinfo
|
CVE-2020-13291
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210808
|
7.2 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
|
CWE-287
Improper Authentication
|
CVE-2020-13290
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210809
|
4.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page
|
CWE-79
Cross-site Scripting
|
CVE-2020-13288
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210810
|
6.1 |
MEDIUM
Network
|
rosariosis
|
student_information_system
|
Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13278
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|