In Gogs version 0.13.0 a high severity vulnerability CVE-2024-39933 was detected. This vulnerability allows attackers to access the code in a new release. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39933/.
Read more Developer ToolsIn Gogs through 0.13.0 a critical severity vulnerability CVE-2024-39931 was detected. It allows deletion of internal files. There is currently no solution available for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39931.
Read more Developer ToolsIn Gogs versions up to 0.13.0 a critical severity vulnerability CVE-2024-39930 was detected in the built-in SSH server. This flaw lets attackers send harmful commands, leading to remote code execution. Attackers must be authenticated and can exploit this if the SSH server is enabled. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39930.
Read more Developer ToolsIn GitLab version 17.1 a medium severity vulnerability CVE-2024-1493 was detected. This vulnerability allows attackers to DoS attack on the server. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-1493/.
Read more Developer ToolsIn GitLab versions from 16.7 to 17.1.1 a medium severity vulnerability CVE-2024-3959 was detected. This vulnerability allows attackers to get access to sensitive data. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-3959/.
Read more Developer ToolsIn GitLab EE all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 a medium severity vulnerability CVE-2024-3115 was detected. Attackers can access issues and epics without an SSO session through Duo Chat. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-3115.
Read more Developer ToolsIn GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 a medium severity vulnerability CVE-2024-1816 was detected. This problem lets an attacker crash a service by using a specially made OpenAPI file. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-1816.
Read more Developer ToolsIn GitLab CE/EE versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 a medium severity vulnerability CVE-2024-2191 was detected. This vulnerability makes the merge request title publicly visible despite being set to project members only, failing to restrict access from unauthorized users. To address this issue users should upgrade to 16.11.5, 17.0.3 or 17.1.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-2191.
In GitLab CE/EE versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 a high severity vulnerability CVE-2024-4901 was detected. A stored XSS vulnerability involves injecting malicious code into a web app via user inputs like commit notes. This allows attackers to run scripts in users’ browsers, compromising sessions or accessing sensitive data. To address this issue users should upgrade to 16.11.5, 17.0.3 or 17.1.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-4901.
Read more Developer Tools