[@ngalog](https://hackerone.com/ngalog)
3 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2021-22171No exploit | Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if thgitlab · gitlab · CWE-287 | Medium6.5 | — | 1.3% | Jan 15, 2021 |
17Monitor | CVE-2020-13350No exploit | CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators togitlab · gitlab · CWE-352 | Medium4.3 | — | 0.8% | Nov 17, 2020 |
26Monitor | CVE-2020-13324No exploit | A vulnerability was discovered in GitLab versions prior to 13.1.gitlab · gitlab | Medium6.5 | — | 1.0% | Sep 30, 2020 |
- CVE-2021-2217126Monitor
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if th
MediumCVSS 6.5No exploitEPSS 1%gitlab · gitlabJan 15, 2021
- CVE-2020-1335017Monitor
CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to
MediumCVSS 4.3No exploitEPSS 1%gitlab · gitlabNov 17, 2020
- CVE-2020-1332426Monitor
A vulnerability was discovered in GitLab versions prior to 13.1.
MediumCVSS 6.5No exploitEPSS 1%gitlab · gitlabSep 30, 2020