Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 556

Количество 4 556

github логотип

GHSA-xxx4-cx36-38r5

около 3 лет назад

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxw9-chfj-mp3c

11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xxcc-244v-rj6x

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

CVSS3: 8.7
EPSS: Средний
github логотип

GHSA-xv46-hhwp-vf34

около 3 лет назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-xrj7-5h89-vjmj

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

EPSS: Низкий
github логотип

GHSA-xq89-553h-3j4m

около 3 лет назад

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xpwh-4xmj-5wrc

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xpg3-c2hf-x9vf

почти 3 года назад

A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xjw7-jpqw-3q4x

около 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xhg3-wf98-646c

около 3 лет назад

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

EPSS: Низкий
github логотип

GHSA-xh98-rwp8-8rpw

9 месяцев назад

An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xh8q-q4r3-6x29

больше 3 лет назад

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

EPSS: Низкий
github логотип

GHSA-xh7q-hg94-4g3m

больше 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xh3c-jh29-g5wj

почти 2 года назад

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xgmj-r659-f4c7

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xg8m-gfp3-4fv6

около 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

EPSS: Низкий
github логотип

GHSA-xg8m-4qxg-vm4m

около 2 лет назад

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xg29-cfqc-hqpr

около 3 лет назад

An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xfxc-c47w-9432

около 3 лет назад

An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xcw3-xf4g-cwjj

больше 2 лет назад

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxx4-cx36-38r5

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxw9-chfj-mp3c

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

CVSS3: 2.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxcc-244v-rj6x

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

CVSS3: 8.7
31%
Средний
больше 1 года назад
github логотип
GHSA-xv46-hhwp-vf34

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xrj7-5h89-vjmj

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xq89-553h-3j4m

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 4.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-xpwh-4xmj-5wrc

An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpg3-c2hf-x9vf

A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.

CVSS3: 3.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xjw7-jpqw-3q4x

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xhg3-wf98-646c

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xh98-rwp8-8rpw

An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.

CVSS3: 3.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xh8q-q4r3-6x29

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xh7q-hg94-4g3m

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh3c-jh29-g5wj

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xgmj-r659-f4c7

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xg8m-gfp3-4fv6

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xg8m-4qxg-vm4m

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 3.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xg29-cfqc-hqpr

An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xfxc-c47w-9432

An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xcw3-xf4g-cwjj

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 7.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу