Search CVE reports


Toggle filters

591 – 600 of 1533 results


CVE-2022-4037

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-3870

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-3613

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-3573

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-3514

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2018-25060

Medium priority
Vulnerable

A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown functionality of the file csrf.go. The manipulation of the argument Generate leads to sensitive cookie without secure...

1 affected package

golang-github-go-macaron-csrf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-macaron-csrf Not in release Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2022-3064

Medium priority

Some fixes available 3 of 33

Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.

6 affected packages

golang-github-coreos-discovery-etcd-io, golang-gopkg-yaml.v3, golang-yaml.v2, kubernetes, webhook, singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-coreos-discovery-etcd-io Vulnerable Vulnerable Vulnerable Not in release
golang-gopkg-yaml.v3 Not affected Not affected Not in release Not in release
golang-yaml.v2 Not affected Not affected Fixed Fixed
kubernetes Not affected Not affected Not affected Not in release
webhook Needs evaluation Needs evaluation Needs evaluation Needs evaluation
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2022-2582

Medium priority
Needs evaluation

The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks...

1 affected package

golang-github-aws-aws-sdk-go

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-aws-aws-sdk-go Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-4239

Medium priority
Needs evaluation

The Noise protocol implementation suffers from weakened cryptographic security after encrypting 2^64 messages, and a potential denial of service attack. After 2^64 (~18.4 quintillion) messages are encrypted with the Encrypt...

1 affected package

golang-github-flynn-noise

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-flynn-noise Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-4238

Medium priority
Needs evaluation

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This...

1 affected package

golang-github-masterminds-goutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-masterminds-goutils Needs evaluation Needs evaluation Not in release Not in release
Show less packages