Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2021
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
CVSS Score
5.3
EPSS Score
0.001
Published
2021-10-05
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-10-05
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-10-05
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
CVSS Score
5.3
EPSS Score
0.004
Published
2021-10-05
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-10-05
Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-10-05
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
CVSS Score
5.4
EPSS Score
0.003
Published
2021-10-05
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
CVSS Score
6.5
EPSS Score
0.001
Published
2021-10-05
Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-10-05
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.
CVSS Score
7.2
EPSS Score
0.095
Published
2021-10-05


Contact Us

Shodan ® - All rights reserved