Search CVE reports


Toggle filters

661 – 670 of 1538 results


CVE-2022-2455

Medium priority
Ignored

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-2428

Medium priority
Ignored

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-42906

Medium priority
Needs evaluation

powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When...

1 affected package

powerline-gitstatus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
powerline-gitstatus Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-39237

Medium priority
Vulnerable

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure...

2 affected packages

golang-github-sylabs-sif, singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sylabs-sif Not affected Vulnerable Vulnerable Not in release
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2022-40083

Medium priority
Needs evaluation

Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).

4 affected packages

golang-github-labstack-echo, golang-github-labstack-echo.v2, golang-github-labstack-echo.v3, golang-github-labstack-gommon

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-labstack-echo Needs evaluation Needs evaluation Not in release Not in release
golang-github-labstack-echo.v2 Not in release Needs evaluation Needs evaluation Not in release
golang-github-labstack-echo.v3 Not in release Needs evaluation Needs evaluation Not in release
golang-github-labstack-gommon Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-2990

Medium priority
Needs evaluation

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where...

1 affected package

golang-github-containers-buildah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-buildah Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2022-38183

Low priority
Needs evaluation

In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the...

2 affected packages

golang-code.gitea-git, golang-code.gitea-sdk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-code.gitea-git Not in release Needs evaluation Needs evaluation Needs evaluation
golang-code.gitea-sdk Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-2539

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2022-2534

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2022-2531

Medium priority
Ignored

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was not performing correct...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages