Show filters
2,016 Total Results
Displaying 171-180 of 2,016
Sort by:
Attacker Value
Unknown
CVE-2024-7610
Disclosure Date: August 08, 2024 (last updated August 30, 2024)
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.
0
Attacker Value
Unknown
CVE-2024-7554
Disclosure Date: August 08, 2024 (last updated August 30, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.
0
Attacker Value
Unknown
CVE-2024-5423
Disclosure Date: August 08, 2024 (last updated August 30, 2024)
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.
0
Attacker Value
Unknown
CVE-2024-4207
Disclosure Date: August 08, 2024 (last updated August 30, 2024)
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.
0
Attacker Value
Unknown
CVE-2024-3958
Disclosure Date: August 08, 2024 (last updated August 30, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.
0
Attacker Value
Unknown
CVE-2024-3958
Disclosure Date: August 08, 2024 (last updated August 30, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.
0
Attacker Value
Unknown
CVE-2024-3114
Disclosure Date: August 08, 2024 (last updated August 24, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.
0
Attacker Value
Unknown
CVE-2024-3035
Disclosure Date: August 08, 2024 (last updated August 30, 2024)
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.
0
Attacker Value
Unknown
CVE-2024-2800
Disclosure Date: August 08, 2024 (last updated August 24, 2024)
ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.
0
Attacker Value
Unknown
CVE-2024-6329
Disclosure Date: August 08, 2024 (last updated August 24, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.
0