GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
NVD-CWE-noinfo
CVE-2020-1553
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka ‘Windows Runtime Elevation of Privilege Vulnerability’.
CVE-2020-15541
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
CVE-2020-15542
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
CVE-2020-1556
An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka ‘Windows WalletService Elevation of Privilege Vulnerability’. This CVE ID is unique from CVE-2020-1533.
CVE-2020-1548
An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka ‘Windows WaasMedic Service Information Disclosure Vulnerability’.
