Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-65jc-pvp3-rxq3

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

EPSS: Низкий
github логотип

GHSA-64x3-qr9c-w6jw

почти 4 года назад

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-64vr-2vhr-px3r

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-64p4-8fvv-rw89

больше 2 лет назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-6482-jw4x-5vc6

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

EPSS: Низкий
github логотип

GHSA-6463-hw74-9748

почти 4 года назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

EPSS: Низкий
github логотип

GHSA-645m-h3pw-m72w

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-637p-mqw3-h377

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

EPSS: Низкий
github логотип

GHSA-62f3-w8qm-86g2

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-625m-28mg-rq98

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6224-476v-jppq

почти 4 года назад

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-5xvc-mqqw-gm7p

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It allows Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-5xrw-g5h5-j2r6

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-5xhg-wqm3-8ww2

больше 2 лет назад

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-5x88-x3vg-442p

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-5x78-2px4-46jf

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

EPSS: Низкий
github логотип

GHSA-5vxp-7m3v-hxrg

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

EPSS: Низкий
github логотип

GHSA-5vpg-xw87-4738

5 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain circumstances, could have allowed an attacker to remove Duo flows of another user.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5rfm-2gcw-59ww

больше 2 лет назад

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-5qxw-jpqh-h83p

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-65jc-pvp3-rxq3

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-64x3-qr9c-w6jw

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-64vr-2vhr-px3r

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-64p4-8fvv-rw89

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6482-jw4x-5vc6

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6463-hw74-9748

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

0%
Низкий
почти 4 года назад
github логотип
GHSA-645m-h3pw-m72w

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-637p-mqw3-h377

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

0%
Низкий
почти 4 года назад
github логотип
GHSA-62f3-w8qm-86g2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-625m-28mg-rq98

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6224-476v-jppq

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 5.4
2%
Низкий
почти 4 года назад
github логотип
GHSA-5xvc-mqqw-gm7p

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It allows Uncontrolled Resource Consumption.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5xrw-g5h5-j2r6

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider.

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-5xhg-wqm3-8ww2

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5x88-x3vg-442p

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5x78-2px4-46jf

An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

0%
Низкий
почти 4 года назад
github логотип
GHSA-5vxp-7m3v-hxrg

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5vpg-xw87-4738

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain circumstances, could have allowed an attacker to remove Duo flows of another user.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-5rfm-2gcw-59ww

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5qxw-jpqh-h83p

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 4.3
0%
Низкий
около 4 лет назад

Уязвимостей на страницу