Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

David Fernandez

#26595of 53,635
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-21530
5.3
2022-10-17
Gitlab · Gitlab Ce/Ee · CVE-2022-3286
**Name of the Vulnerable Software and Affected Versions** GitLab EE versions 14.2 through 15.2.4 GitLab EE versions 15.3 through 15.3.3 GitLab EE versions 15.4 through 15.4.0 **Description** The issue is related to a lack of IP address checking in GitLab EE, which allows a group member to bypass IP restrictions when using a deploy token. **Recommendations** For versions 14.2 through 15.2.4, update to version 15.2.5 or later. For versions 15.3 through 15.3.3, update to version 15.3.4 or later. For versions 15.4 through 15.4.0, update to version 15.4.1 or later.
PT-2022-13881
4.3
2022-05-11
Gitlab · Gitlab · CVE-2022-1428
**Name of the Vulnerable Software and Affected Versions** GitLab versions prior to 14.8.6 GitLab versions 14.9 through 14.9.4 GitLab versions 14.10 through 14.10.1 **Description** The issue in GitLab arises from incorrect verification of throttling limits for authenticated package requests, resulting in these limits not being enforced. **Recommendations** For versions prior to 14.8.6, update to version 14.8.6 or later. For versions 14.9 through 14.9.3, update to version 14.9.4 or later. For versions 14.10 through 14.10.0, update to version 14.10.1 or later.