Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 943

Количество 5 943

github логотип

GHSA-76vq-h32w-9w3v

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-76v4-rwr7-cgr3

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-76g9-63cr-m776

больше 4 лет назад

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.x, between 14.5.0 and 14.5.x, and between 14.6.0 and 14.6.x would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7668-4r26-7chc

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-762x-jmwj-7xmj

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-75xv-qqv2-qh22

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

EPSS: Низкий
github логотип

GHSA-75xf-j8f2-9vxq

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-75fp-hxc3-f56v

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-75cm-h3qp-7jq4

больше 3 лет назад

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-7579-pf64-fxw7

около 4 лет назад

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

EPSS: Низкий
github логотип

GHSA-74q6-7f58-9g77

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-74mh-x92q-wp74

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-74cm-4qqj-22p4

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-747q-6mj3-hj66

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

EPSS: Низкий
github логотип

GHSA-73w2-5f6g-jx42

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-73p8-f56m-692w

около 2 лет назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7367-wp6r-gcqc

29 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-727w-x522-pvpc

около 4 лет назад

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-722v-49rj-hh57

около 3 лет назад

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-6xw3-8926-pq6q

около 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-76vq-h32w-9w3v

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

1%
Низкий
около 4 лет назад
github логотип
GHSA-76v4-rwr7-cgr3

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-76g9-63cr-m776

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.x, between 14.5.0 and 14.5.x, and between 14.6.0 and 14.6.x would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-7668-4r26-7chc

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-762x-jmwj-7xmj

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-75xv-qqv2-qh22

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

1%
Низкий
около 4 лет назад
github логотип
GHSA-75xf-j8f2-9vxq

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-75fp-hxc3-f56v

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

1%
Низкий
около 4 лет назад
github логотип
GHSA-75cm-h3qp-7jq4

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-7579-pf64-fxw7

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

2%
Низкий
около 4 лет назад
github логотип
GHSA-74q6-7f58-9g77

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-74mh-x92q-wp74

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-74cm-4qqj-22p4

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
6%
Низкий
около 2 лет назад
github логотип
GHSA-747q-6mj3-hj66

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

1%
Низкий
около 4 лет назад
github логотип
GHSA-73w2-5f6g-jx42

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-73p8-f56m-692w

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-7367-wp6r-gcqc

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

CVSS3: 8.7
0%
Низкий
29 дней назад
github логотип
GHSA-727w-x522-pvpc

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-722v-49rj-hh57

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVSS3: 4.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-6xw3-8926-pq6q

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

1%
Низкий
около 4 лет назад

Уязвимостей на страницу