Show filters
1,948 Total Results
Displaying 81-90 of 1,948
Sort by:
Attacker Value
Unknown
CVE-2024-8179
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.
0
Attacker Value
Unknown
CVE-2024-12570
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.
0
Attacker Value
Unknown
CVE-2024-12292
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.
0
Attacker Value
Unknown
CVE-2024-11274
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.
0
Attacker Value
Unknown
CVE-2024-10043
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.
0
Attacker Value
Unknown
CVE-2024-10240
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.
0
Attacker Value
Unknown
CVE-2024-8237
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file.
0
Attacker Value
Unknown
CVE-2024-8177
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.
0
Attacker Value
Unknown
CVE-2024-8114
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.
0
Attacker Value
Unknown
CVE-2024-11828
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch.
0