|
223781
|
4.9 |
MEDIUM
Network
|
nextcloud
|
nextcloud
|
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notific…
|
NVD-CWE-Other
|
CVE-2019-15611
|
2024-11-21 13:29 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223782
|
4.3 |
MEDIUM
Network
|
nextcloud
|
circles
|
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.
|
NVD-CWE-Other
|
CVE-2019-15610
|
2024-11-21 13:29 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223783
|
5.4 |
MEDIUM
Network
|
nodered
|
node-red
|
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session c…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15607
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223784
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the G…
|
NVD-CWE-Other
|
CVE-2019-15590
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223785
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15586
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223786
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted …
|
CWE-287
Improper Authentication
|
CVE-2019-15585
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223787
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, th…
|
CWE-200
Information Exposure
|
CVE-2019-15583
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223788
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-15582
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223789
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group vi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-15581
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223790
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project …
|
NVD-CWE-noinfo
|
CVE-2019-15579
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|