Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2021-39882

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
Attacker Value
Unknown

CVE-2021-39867

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
Attacker Value
Unknown

CVE-2021-39875

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.
Attacker Value
Unknown

CVE-2021-39869

Disclosure Date: October 05, 2021 (last updated November 28, 2024)
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
Attacker Value
Unknown

CVE-2021-39872

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
Attacker Value
Unknown

CVE-2021-39866

Disclosure Date: October 05, 2021 (last updated November 28, 2024)
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
Attacker Value
Unknown

CVE-2021-39873

Disclosure Date: October 04, 2021 (last updated November 28, 2024)
In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.
Attacker Value
Unknown

CVE-2021-39871

Disclosure Date: October 04, 2021 (last updated November 28, 2024)
In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.
Attacker Value
Unknown

CVE-2021-39868

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.