|
222801
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted …
|
CWE-287
Improper Authentication
|
CVE-2019-15585
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222802
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, th…
|
CWE-200
Information Exposure
|
CVE-2019-15583
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222803
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-15582
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222804
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group vi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-15581
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222805
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project …
|
NVD-CWE-noinfo
|
CVE-2019-15579
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222806
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be di…
|
CWE-200
Information Exposure
|
CVE-2019-15578
|
2024-11-21 13:29 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222807
|
9.1 |
CRITICAL
Network
|
cisco
|
smart_software_manager_on-prem
|
A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to change user account information which can pre…
|
CWE-20
Improper Input Validation
|
CVE-2019-16029
|
2024-11-21 13:29 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222808
|
6.5 |
MEDIUM
Network
|
cisco
|
ios_xr
|
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated,…
|
CWE-20
Improper Input Validation
|
CVE-2019-16027
|
2024-11-21 13:29 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222809
|
5.9 |
MEDIUM
Network
|
cisco
|
staros
|
A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management Entity (MME) could allow an unauthenticated, remote attacker to cause a denial of…
|
CWE-20
Improper Input Validation
|
CVE-2019-16026
|
2024-11-21 13:29 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222810
|
6.1 |
MEDIUM
Network
|
cisco
|
crosswork_change_automation crosswork_network_automation
|
A vulnerability in the web-based management interface of Cisco Crosswork Change Automation could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a use…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16024
|
2024-11-21 13:29 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|