• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

NVD-CWE-noinfo

CVE-2021-39866

February 23, 2023 by

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVE-2021-39869

February 23, 2023 by

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVE-2021-39870

February 23, 2023 by

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

CVE-2021-39871

February 23, 2023 by

In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.

CVE-2021-39873

February 23, 2023 by

In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.

CVE-2021-39874

February 23, 2023 by

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1538
  • Go to page 1539
  • Go to page 1540
  • Go to page 1541
  • Go to page 1542
  • Interim pages omitted …
  • Go to page 2387
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE