Search CVE reports


Toggle filters

981 – 990 of 1541 results


CVE-2020-26414

Medium priority
Ignored

An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-3028

Medium priority
Needs evaluation

git-big-picture before 1.0.0 mishandles ' characters in a branch name, leading to code execution.

1 affected package

git-big-picture

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git-big-picture Needs evaluation Needs evaluation Needs evaluation Not in release Ignored
Show less packages

CVE-2020-36067

Medium priority
Needs evaluation

GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.

1 affected package

golang-github-tidwall-gjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-tidwall-gjson Needs evaluation Needs evaluation Needs evaluation Ignored Not in release
Show less packages

CVE-2020-36066

Medium priority
Needs evaluation

GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.

1 affected package

golang-github-tidwall-gjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-tidwall-gjson Needs evaluation Needs evaluation Needs evaluation Ignored Not in release
Show less packages

CVE-2020-35381

Medium priority
Vulnerable

jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.

1 affected package

golang-github-buger-jsonparser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-buger-jsonparser Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-35380

Medium priority
Vulnerable

GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.

1 affected package

golang-github-tidwall-gjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-tidwall-gjson Vulnerable Vulnerable Vulnerable Vulnerable Not in release
Show less packages

CVE-2020-26411

Low priority
Ignored

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement...

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-26417

Medium priority
Ignored

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-26416

Medium priority
Ignored

Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-26415

Medium priority
Ignored

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages