Search CVE reports


Toggle filters

971 – 980 of 1535 results


CVE-2021-22171

Medium priority
Not affected

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2021-22168

Medium priority
Ignored

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-22167

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-22166

Medium priority
Ignored

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-26414

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-3028

Medium priority
Needs evaluation

git-big-picture before 1.0.0 mishandles ' characters in a branch name, leading to code execution.

1 affected package

git-big-picture

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git-big-picture Needs evaluation Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2020-36067

Medium priority
Needs evaluation

GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.

1 affected package

golang-github-tidwall-gjson

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-tidwall-gjson Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-36066

Medium priority
Needs evaluation

GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.

1 affected package

golang-github-tidwall-gjson

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-tidwall-gjson Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-35381

Medium priority
Vulnerable

jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.

1 affected package

golang-github-buger-jsonparser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-buger-jsonparser Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-35380

Medium priority
Vulnerable

GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.

1 affected package

golang-github-tidwall-gjson

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-tidwall-gjson Vulnerable Vulnerable Vulnerable Not in release
Show less packages