Show filters
1,948 Total Results
Displaying 81-90 of 1,948
Sort by:
Attacker Value
Unknown

CVE-2024-8179

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.
0
Attacker Value
Unknown

CVE-2024-12570

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.
0
Attacker Value
Unknown

CVE-2024-12292

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.
0
Attacker Value
Unknown

CVE-2024-11274

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.
0
Attacker Value
Unknown

CVE-2024-10043

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.
0
Attacker Value
Unknown

CVE-2024-10240

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.
Attacker Value
Unknown

CVE-2024-8237

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file.
Attacker Value
Unknown

CVE-2024-8177

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.
Attacker Value
Unknown

CVE-2024-8114

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.
Attacker Value
Unknown

CVE-2024-11828

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch.