[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2017-0920
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

CVE-2018-8971
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

*OVAL
oval:org.secpod.oval:def:53331
CPE    214
cpe:/a:gitlab:gitlab:8.15.7::~~community~~~
cpe:/a:gitlab:gitlab:9.2.2::~~enterprise~~~
cpe:/a:gitlab:gitlab:9.5.7::~~enterprise~~~
cpe:/a:gitlab:gitlab:9.4.2::~~community~~~
...

© SecPod Technologies