|
208361
|
4.4 |
MEDIUM
Local
|
gitlab
|
gitlab
|
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-26416
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208362
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=1…
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2020-26415
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208363
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
|
CWE-200
Information Exposure
|
CVE-2020-26413
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208364
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.
|
NVD-CWE-noinfo
|
CVE-2020-26412
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208365
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's p…
|
CWE-862
Missing Authorization
|
CVE-2020-26408
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208366
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.
|
CWE-20 CWE-400
Improper Input Validation Uncontrolled Resource Consumption
|
CVE-2020-26409
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208367
|
3.3 |
LOW
Local
|
google
|
tensorflow
|
In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend. This can result in a q…
|
CWE-20
Improper Input Validation
|
CVE-2020-26270
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208368
|
7.5 |
HIGH
Network
|
google
|
tensorflow
|
In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the direc…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-26269
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208369
|
7.8 |
HIGH
Local
|
google
|
tensorflow
|
In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_format attributes. The code assumes that these two arguments define a permutation o…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-26267
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208370
|
5.3 |
MEDIUM
Local
|
google
|
tensorflow
|
In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-26266
|
2024-11-21 14:19 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|