Log

ASA-202106-24 created at 09 Jun 2021 08:41:05
ASA-202106-23 edited at 09 Jun 2021 08:38:42
Impact
+ A remote attacker could crash the HTTP server using a crafted HTTP/2 request.
ASA-202106-23 created at 09 Jun 2021 08:37:29
ASA-202106-22 edited at 09 Jun 2021 08:37:17
Impact
+ A remote attacker could execute arbitrary code using a crafted email message.
ASA-202106-22 created at 09 Jun 2021 08:36:23
CVE-2021-22220 edited at 09 Jun 2021 08:36:00
Description
- An issue has been discovered in GitLab affecting all versions starting with 13.10 before 13.12.2. GitLab was vulnerable to a stored cross-site scripting (XSS) attack in blob viewer of notebooks.
+ An issue has been discovered in GitLab affecting all versions starting with 13.10 before 13.12.2. GitLab was vulnerable to a stored cross-site scripting (XSS) attack in the blob viewer of notebooks.
CVE-2021-22221 edited at 09 Jun 2021 08:34:47
Description
- An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired.
+ An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.12.2. Insufficient expired password validation in various operations allowed users to maintain limited access after their password expired.
References
https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
https://gitlab.com/gitlab-org/gitlab/-/issues/292006
ASA-202106-21 edited at 09 Jun 2021 08:34:18
Impact
+ A remote attacker could disclose sensitive information, bypass authentication, execute JavaScript code using cross-site scripting, spoof content or crash the GitLab server.
ASA-202106-21 created at 09 Jun 2021 08:31:07
ASA-202106-20 edited at 09 Jun 2021 08:30:59
Impact
+ Requesting environment variables with crafted contents could lead to arbitrary code execution in a telnet client. Additionally an unauthenticated remote attacker could execute arbitrary code on a telnet server via crafted telnet packets.