|
212031
|
8.8 |
HIGH
Network
|
gitlab
|
runner
|
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13295
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212032
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
|
NVD-CWE-noinfo
|
CVE-2020-13294
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212033
|
7.1 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
|
NVD-CWE-noinfo
|
CVE-2020-13293
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212034
|
9.6 |
CRITICAL
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
|
CWE-287
Improper Authentication
|
CVE-2020-13292
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212035
|
8.8 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.
|
CWE-352
Origin Validation Error
|
CVE-2020-12781
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212036
|
7.5 |
HIGH
Network
|
combodo
|
itop
|
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12780
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212037
|
5.4 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12779
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212038
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12778
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212039
|
7.5 |
HIGH
Network
|
combodo
|
itop
|
A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.
|
CWE-200
Information Exposure
|
CVE-2020-12777
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212040
|
9.8 |
CRITICAL
Network
|
aerospike
|
aerospike_server
|
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code exe…
|
CWE-78
OS Command
|
CVE-2020-13151
|
2024-11-21 14:00 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|