Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2021-39882
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
0
Attacker Value
Unknown
CVE-2021-39867
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
0
Attacker Value
Unknown
CVE-2021-39875
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.
0
Attacker Value
Unknown
CVE-2021-39869
Disclosure Date: October 05, 2021 (last updated November 28, 2024)
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
0
Attacker Value
Unknown
CVE-2021-39872
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
0
Attacker Value
Unknown
CVE-2021-39866
Disclosure Date: October 05, 2021 (last updated November 28, 2024)
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
0
Attacker Value
Unknown
CVE-2021-39873
Disclosure Date: October 04, 2021 (last updated November 28, 2024)
In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.
0
Attacker Value
Unknown
CVE-2021-39871
Disclosure Date: October 04, 2021 (last updated November 28, 2024)
In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.
0
Attacker Value
Unknown
CVE-2021-39868
Disclosure Date: October 04, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.
0