CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
GitLab through 12.7.2 allows XSS.
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
GitLab EE 11.0 and later through 12.7.2 allows XSS.
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).
