6.4

CVSS3.1

CVE-2022-31669 - Harbor fails to validate the user permissions when updating tag immutability policies

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies co…

📅 Published: Nov. 14, 2024, 11:48 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:20 p.m.

7.7

CVSS3.1

CVE-2022-31670 - Harbor fails to validate the user permissions when updating tag retention policies

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured …

📅 Published: Nov. 14, 2024, 11:45 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:20 p.m.

7.4

CVSS3.1

CVE-2022-31671 - Harbor fails to validate the user permissions when reading and updating job execution logs through …

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs sto…

📅 Published: Nov. 14, 2024, 11:42 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:40 p.m.

7.7

CVSS3.1

CVE-2022-31666 - Harbor fails to validate user permissions while Viewing, updating and deleting Webhook policies

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

📅 Published: Nov. 14, 2024, 11:32 a.m. 🔄 Last Modified: July 12, 2025, 10:44 p.m.

5.4

CVSS3.1

CVE-2024-8180 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

📅 Published: Nov. 14, 2024, 11:02 a.m. 🔄 Last Modified: Dec. 13, 2024, 1:26 a.m.

8.5

CVSS3.1

CVE-2024-9693 - Incorrect Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

📅 Published: Nov. 14, 2024, 11:02 a.m. 🔄 Last Modified: Nov. 26, 2024, 1:57 a.m.

9.8

CVSS3.1

CVE-2024-10571 - Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution …

📅 Published: Nov. 14, 2024, 11 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

7.5

CVSS3.1

CVE-2024-47916 - Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Travers…

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

📅 Published: Nov. 14, 2024, 10 a.m. 🔄 Last Modified: Nov. 15, 2024, 1:58 p.m.

7.5

CVSS3.1

CVE-2024-47915 - VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

📅 Published: Nov. 14, 2024, 9:57 a.m. 🔄 Last Modified: Nov. 15, 2024, 1:58 p.m.

4.5

CVSS3.1

CVE-2024-47914 - VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)

VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)

📅 Published: Nov. 14, 2024, 9:56 a.m. 🔄 Last Modified: Nov. 15, 2024, 1:58 p.m.
Total resulsts: 343757
Page 7337 of 34,376
« previous page » next page
Filters