Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In December 2024
An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.
CVSS Score
5.4
EPSS Score
0.0
Published
2024-12-12
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.
CVSS Score
4.3
EPSS Score
0.003
Published
2024-12-12
An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.
CVSS Score
6.4
EPSS Score
0.0
Published
2024-12-12
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption.
CVSS Score
6.5
EPSS Score
0.0
Published
2024-12-12
Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.
CVSS Score
4.4
EPSS Score
0.0
Published
2024-12-12
Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.
CVSS Score
4.3
EPSS Score
0.001
Published
2024-12-12
Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
CVSS Score
4.3
EPSS Score
0.001
Published
2024-12-12
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVSS Score
6.2
EPSS Score
0.0
Published
2024-12-12
An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.
CVSS Score
5.4
EPSS Score
0.002
Published
2024-12-12
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-12-12


Contact Us

Shodan ® - All rights reserved