Security
Headlines
HeadlinesLatestCVEs

Tag

#git

CVE-2023-4008

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.

CVE
#git
GHSA-52h8-c876-989c: Answer has Race Condition within a Thread

Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1.

GHSA-v9vc-7x69-c2x8: Answer Missing Authorization vulnerability

Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.

GHSA-ggcf-hwxp-rc77: Answer Insufficient Session Expiration vulnerability

Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.

GHSA-j63x-f657-2m9g: Answer has Weak Password Requirements

Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.

CVE-2023-3932

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVE-2023-4124

Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.

CVE-2023-4126

Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.

CVE-2023-4127: refactor(votes): refactor user vote repo · answerdev/answer@47661dc

Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1.

CVE-2023-4125: fix(password): password can't contains space. · answerdev/answer@7d23b17

Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.