Authorization Bypass

gitlab is vulnerable to Authorization Bypasses. This vulnerability occurs due to a flaw in the way that GitLab handles GraphQL mutations. An attacker can exploit this vulnerability to perform Git acti ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Cross-Site Request Forgery (CSRF)

gitlab is vulnerable to Cross-Site Request Forgery (CSRF). The vulnerability exists in the GraphQL API, allowing an attacker to call mutations as the victimRead More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Information Disclosure

gitlab is vulnerable to Information Disclosure. This vulnerability occurs due to a flaw in the way that GitLab handles GraphQL queries. An attacker can exploit this vulnerability to access project det ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Improper Authorization

gitlab is vulnerable to Improper Authorization. The vulnerability exists due to improper access to some particular fields through the GraphQL API which allows an attacker to perform unauthorized actio ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Denial Of Service (DoS)

gitlab is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the lack of length validation of the library, which allows an attacker to create a large Issue description via GraphQL, ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Sorare: Operation CreateOrUpdateSo5LineupMutation does not restrict multiple captains

## Summary: By tampering with the POST request to the endpoint CreateOrUpdateSo5LineupMutation while editing a team you can change all football players to have the captain attribute to 'true'. This g ...

Continue Reading
A Data Exfiltration Attack Scenario: The Porsche Experience

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() As part of [**Checkmarx's mission**]() to help organizations develop and dep ...

Continue Reading
Improper Permission Checks

directus is vulnerable to Improper Permission Checks. The vulnerability exists because the permission filters such as `user_created IS $CURRENT_USER` are not properly checked in the library when using ...

Continue Reading

Back to Main

Subscribe for the latest news: