CVEs

All of these CVEs are fixed in the latest stable release of the software.

CVEVersion AffectedBrief Description
CVE-2022-381831.16.8Incorrect Access Control
CVE-2022-307811.16.6Failed to validate migration url for external Github API
CVE-2022-273131.16.3DOS
CVE-2022-19281.16.8XSS Authentication for certain authenticated users
CVE-2022-10581.16.4Open Redirect
CVE-2022-09051.16.3Improper Authorization in PAM for custom built binaries
CVE-2021-453311.5.02FA Token Reuse
CVE-2021-453301.15.7Session Reuse
CVE-2021-453291.5.1XSS Authentication for certain authenticated users
CVE-2021-453281.4.3Open Redirect
CVE-2021-453271.11.2CSRF in certain curcuimstances
CVE-2021-453261.5.1CSRF in certain curcuimstances
CVE-2021-453251.7.0SSRF in OpenID
CVE-2021-33821.13.1DOS via stackoverflow
CVE-2021-291341.13.6Information Disclosure
CVE-2021-283781.13.3XSS Authentication for certain authenticated users
CVE-2020-289911.11.5Vulnerable upstream Library
CVE-2020-132461.11.5DOS via deadlock
CVE-2019-115761.7.52FA Bypass in certain curcuimstances
CVE-2019-112291.7.5Vulnerable upstream Library
CVE-2019-112281.7.5Failed to validate migration url
CVE-2019-10103141.7.3XSS Authentication for certain authenticated users
CVE-2019-10102611.7.0XSS Authentication for certain authenticated users
CVE-2019-10000021.6.2Incorrect Access Control
CVE-2018-189261.5.3Vulnerable upstream Library
CVE-2018-151921.5.0-rc2SSRF in Webhooks
CVE-2018-10008031.5.0Exposure of CWE-200 to users with access to specific repositories