Show filters
2,016 Total Results
Displaying 201-210 of 2,016
Sort by:
Attacker Value
Unknown

CVE-2024-6323

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
Attacker Value
Unknown

CVE-2024-5655

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.
Attacker Value
Unknown

CVE-2024-5430

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.
Attacker Value
Unknown

CVE-2024-4901

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.
Attacker Value
Unknown

CVE-2024-4557

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.
Attacker Value
Unknown

CVE-2024-4011

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.
Attacker Value
Unknown

CVE-2024-3959

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.
Attacker Value
Unknown

CVE-2024-3959

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.
Attacker Value
Unknown

CVE-2024-3115

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.
Attacker Value
Unknown

CVE-2024-2191

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.