Количество 5 501
Количество 5 501
GHSA-5qwh-g35c-5mmm
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.
GHSA-5qpg-r237-3pm4
GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.
GHSA-5qhc-78h9-5m5x
GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.
GHSA-5q5j-r39w-wc64
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.
GHSA-5px4-prjg-wgwv
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.
GHSA-5prc-f4c3-qjpv
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions.
GHSA-5pqm-4gpg-63j8
An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.
GHSA-5phj-qv74-pv4w
Missing permission check in Jenkins GitLab Plugin
GHSA-5p95-g2w7-2rfh
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
GHSA-5p8h-m559-wpw7
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.
GHSA-5p89-g2g5-4687
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.
GHSA-5p65-6rwr-377w
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.
GHSA-5mxj-8vqf-cpf9
An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.
GHSA-5mpx-m64g-xxgq
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
GHSA-5mm2-786g-8qwh
A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group
GHSA-5mjv-86c4-mprj
An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.
GHSA-5mcq-mg28-vj82
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
GHSA-5m57-mhq7-6vhf
Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.
GHSA-5jjr-96vg-hj88
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.
GHSA-5jj4-fh62-42vp
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-5qwh-g35c-5mmm An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data. | CVSS3: 3 | 0% Низкий | больше 1 года назад | |
GHSA-5qpg-r237-3pm4 GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles. | 0% Низкий | почти 4 года назад | ||
GHSA-5qhc-78h9-5m5x GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions. | CVSS3: 3.7 | 0% Низкий | 5 месяцев назад | |
GHSA-5q5j-r39w-wc64 An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request. | CVSS3: 7.6 | 0% Низкий | около 2 лет назад | |
GHSA-5px4-prjg-wgwv An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption. | 0% Низкий | почти 4 года назад | ||
GHSA-5prc-f4c3-qjpv GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions. | CVSS3: 3.5 | 0% Низкий | 19 дней назад | |
GHSA-5pqm-4gpg-63j8 An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
GHSA-5phj-qv74-pv4w Missing permission check in Jenkins GitLab Plugin | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
GHSA-5p95-g2w7-2rfh Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code | 0% Низкий | почти 4 года назад | ||
GHSA-5p8h-m559-wpw7 An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group. | CVSS3: 3.1 | 0% Низкий | больше 2 лет назад | |
GHSA-5p89-g2g5-4687 An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control. | 0% Низкий | почти 4 года назад | ||
GHSA-5p65-6rwr-377w GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs. | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
GHSA-5mxj-8vqf-cpf9 An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control. | 0% Низкий | почти 4 года назад | ||
GHSA-5mpx-m64g-xxgq GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2). | 0% Низкий | почти 4 года назад | ||
GHSA-5mm2-786g-8qwh A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group | 0% Низкий | почти 4 года назад | ||
GHSA-5mjv-86c4-mprj An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-5mcq-mg28-vj82 For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access. | 0% Низкий | почти 4 года назад | ||
GHSA-5m57-mhq7-6vhf Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7. | 0% Низкий | почти 4 года назад | ||
GHSA-5jjr-96vg-hj88 An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to. | 0% Низкий | почти 4 года назад | ||
GHSA-5jj4-fh62-42vp An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility. | CVSS3: 5.3 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу