VYPR

apk package

chainguard/gitlab-operator-fips

pkg:apk/chainguard/gitlab-operator-fips

Vulnerabilities (131)

  • CVE-2018-17536Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.

  • CVE-2018-17455Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge reque

  • CVE-2018-17454Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

  • CVE-2018-17453Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.

  • CVE-2018-17452Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

  • CVE-2018-17451Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

  • CVE-2018-17450Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

  • CVE-2018-17449Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.

  • CVE-2018-15472Apr 15, 2023
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.

  • CVE-2020-14155Jun 15, 2020
    affected < 0fixed 0

    libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

  • CVE-2020-11505Apr 22, 2020
    affected < 0fixed 0

    An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.

  • CVE-2020-10954Mar 27, 2020
    affected < 0fixed 0

    GitLab through 12.9 is affected by a potential DoS in repository archive download.

  • CVE-2020-10081Mar 13, 2020
    affected < 0fixed 0

    GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.

  • CVE-2020-10087Mar 13, 2020
    affected < 0fixed 0

    GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

  • CVE-2019-13003Mar 10, 2020
    affected < 0fixed 0

    An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.

  • CVE-2020-7968Feb 5, 2020
    affected < 0fixed 0

    GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

  • CVE-2020-7973Feb 5, 2020
    affected < 0fixed 0

    GitLab through 12.7.2 allows XSS.

  • CVE-2019-19260Jan 3, 2020
    affected < 0fixed 0

    GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).

  • CVE-2019-19257Jan 3, 2020
    affected < 0fixed 0

    GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).

  • CVE-2019-15584Dec 20, 2019
    affected < 0fixed 0

    A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

Page 3 of 7