c2at3

2 exploits Active since Oct 2020
CVE-2021-22201 GITLAB CRITICAL WORKING POC
GitLab CE/EE <13.9 - Info Disclosure
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.
1 stars
CVSS 9.6
CVE-2020-25200 GITLAB MEDIUM SCANNER
Pritunl 1.29.2145.25 - Username Enumeration via Login Attempt Error Code Discrepancy
Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server will start responding with error 400. Invalid usernames will receive error 401 indefinitely. Note: This has been disputed by the vendor as not a vulnerability. They argue that this is an intended design
CVSS 5.3