Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 556

Количество 4 556

github логотип

GHSA-w37f-8cwf-64g5

около 3 лет назад

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w2rm-x498-v7f9

около 1 года назад

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-w2rf-v2fh-5mjh

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-w2gf-3qqp-3r4x

около 3 лет назад

An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.

EPSS: Низкий
github логотип

GHSA-w2fx-qxhw-34qh

около 3 лет назад

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-w2fr-4vgx-vq96

около 3 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-vx93-hvpm-489j

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

EPSS: Низкий
github логотип

GHSA-vx8w-6r69-h5fv

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vx7c-2qqj-4773

около 3 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

EPSS: Низкий
github логотип

GHSA-vx5g-jgx3-6mx9

около 3 лет назад

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

EPSS: Низкий
github логотип

GHSA-vx2h-m34g-ggpg

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-vwxf-55xh-p3xf

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-vwj5-wr4r-cq36

больше 1 года назад

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-vvcp-5v5p-8jhc

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vrqc-vwgr-qqp5

около 3 лет назад

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-vrgc-533g-v7r4

около 3 лет назад

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vrcq-g4r8-v287

около 3 лет назад

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vr5w-hwpc-cjqr

10 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-vqfr-3pj8-54gm

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-vpx5-hq6c-gr3m

около 3 лет назад

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-w37f-8cwf-64g5

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-w2rm-x498-v7f9

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

CVSS3: 4.4
0%
Низкий
около 1 года назад
github логотип
GHSA-w2rf-v2fh-5mjh

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-w2gf-3qqp-3r4x

An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.

0%
Низкий
около 3 лет назад
github логотип
GHSA-w2fx-qxhw-34qh

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
5%
Низкий
около 3 лет назад
github логотип
GHSA-w2fr-4vgx-vq96

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-vx93-hvpm-489j

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vx8w-6r69-h5fv

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-vx7c-2qqj-4773

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vx5g-jgx3-6mx9

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vx2h-m34g-ggpg

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 4.4
6%
Низкий
около 2 лет назад
github логотип
GHSA-vwxf-55xh-p3xf

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).

CVSS3: 3.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-vwj5-wr4r-cq36

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-vvcp-5v5p-8jhc

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-vrqc-vwgr-qqp5

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.8
91%
Критический
около 3 лет назад
github логотип
GHSA-vrgc-533g-v7r4

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-vrcq-g4r8-v287

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-vr5w-hwpc-cjqr

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-vqfr-3pj8-54gm

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vpx5-hq6c-gr3m

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу