Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-5f6w-rj6x-7j7v

больше 3 лет назад

Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

EPSS: Низкий
github логотип

GHSA-5cm7-w622-g3vc

больше 3 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-5c73-fgcq-grvm

больше 3 лет назад

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-59q4-w53p-6vq9

больше 3 лет назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

EPSS: Низкий
github логотип

GHSA-58vv-56m5-q92p

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 5.4
EPSS: Высокий
github логотип

GHSA-58jq-vjfq-8v45

больше 1 года назад

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-58hc-8hp4-v536

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-58g4-wwj5-gcwg

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

EPSS: Высокий
github логотип

GHSA-589m-6r98-q925

больше 3 лет назад

GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.

EPSS: Низкий
github логотип

GHSA-583x-8qh5-95fx

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-57q7-86j2-69v6

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

EPSS: Низкий
github логотип

GHSA-57pj-jxfw-3mpj

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.

EPSS: Низкий
github логотип

GHSA-57fv-c5qh-rxvp

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-57c2-x23h-8mc3

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-5733-m8xv-f92m

почти 4 года назад

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-56q9-jqvf-whqc

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

EPSS: Низкий
github логотип

GHSA-56mp-522g-cw9g

больше 3 лет назад

An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules.

EPSS: Низкий
github логотип

GHSA-5642-rrwq-qg29

больше 3 лет назад

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.

EPSS: Низкий
github логотип

GHSA-562h-vcm3-9w8r

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 4 of 5).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-55ff-j47x-6xcq

больше 3 лет назад

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5f6w-rj6x-7j7v

Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5cm7-w622-g3vc

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5c73-fgcq-grvm

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-59q4-w53p-6vq9

For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-58vv-56m5-q92p

An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 5.4
78%
Высокий
почти 3 года назад
github логотип
GHSA-58jq-vjfq-8v45

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-58hc-8hp4-v536

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-58g4-wwj5-gcwg

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

81%
Высокий
больше 3 лет назад
github логотип
GHSA-589m-6r98-q925

GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-583x-8qh5-95fx

An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-57q7-86j2-69v6

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-57pj-jxfw-3mpj

An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-57fv-c5qh-rxvp

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-57c2-x23h-8mc3

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-5733-m8xv-f92m

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-56q9-jqvf-whqc

An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-56mp-522g-cw9g

An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5642-rrwq-qg29

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-562h-vcm3-9w8r

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 4 of 5).

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-55ff-j47x-6xcq

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу