Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-5mxj-8vqf-cpf9

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-5mpx-m64g-xxgq

больше 3 лет назад

GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).

EPSS: Низкий
github логотип

GHSA-5mm2-786g-8qwh

больше 3 лет назад

A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

EPSS: Низкий
github логотип

GHSA-5mjv-86c4-mprj

11 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-5mcq-mg28-vj82

больше 3 лет назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

EPSS: Низкий
github логотип

GHSA-5m57-mhq7-6vhf

больше 3 лет назад

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

EPSS: Низкий
github логотип

GHSA-5jjr-96vg-hj88

больше 3 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

EPSS: Низкий
github логотип

GHSA-5jj4-fh62-42vp

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5jfm-fvc2-73xf

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5jcx-pvq7-vfwp

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

EPSS: Низкий
github логотип

GHSA-5jcc-9fq5-wvh8

больше 3 лет назад

In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.

EPSS: Низкий
github логотип

GHSA-5hrw-2pjr-f25r

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.

EPSS: Низкий
github логотип

GHSA-5h7x-5p3m-j723

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious maintainer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-5h2j-25xj-vggw

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-5h2f-9v3w-h48r

больше 2 лет назад

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5ggg-p758-cx97

больше 3 лет назад

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-5g3m-ghqj-8gwf

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a malicious user could bypass that restriction by sending a specific query to the API endpoint.

EPSS: Низкий
github логотип

GHSA-5fw4-hg92-mgm7

больше 3 лет назад

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-5fpq-xm8v-3843

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-5fmm-qcg5-xxr7

почти 4 года назад

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5mxj-8vqf-cpf9

An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5mpx-m64g-xxgq

GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5mm2-786g-8qwh

A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5mjv-86c4-mprj

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-5mcq-mg28-vj82

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5m57-mhq7-6vhf

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5jjr-96vg-hj88

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5jj4-fh62-42vp

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-5jfm-fvc2-73xf

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5jcx-pvq7-vfwp

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5jcc-9fq5-wvh8

In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5hrw-2pjr-f25r

An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5h7x-5p3m-j723

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious maintainer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-5h2j-25xj-vggw

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

CVSS3: 3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5h2f-9v3w-h48r

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5ggg-p758-cx97

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-5g3m-ghqj-8gwf

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a malicious user could bypass that restriction by sending a specific query to the API endpoint.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5fw4-hg92-mgm7

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-5fpq-xm8v-3843

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-5fmm-qcg5-xxr7

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 6.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу