Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-5qwh-g35c-5mmm

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-5qpg-r237-3pm4

почти 4 года назад

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

EPSS: Низкий
github логотип

GHSA-5qhc-78h9-5m5x

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-5q5j-r39w-wc64

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-5px4-prjg-wgwv

почти 4 года назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-5prc-f4c3-qjpv

19 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-5pqm-4gpg-63j8

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5phj-qv74-pv4w

почти 4 года назад

Missing permission check in Jenkins GitLab Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5p95-g2w7-2rfh

почти 4 года назад

Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

EPSS: Низкий
github логотип

GHSA-5p8h-m559-wpw7

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-5p89-g2g5-4687

почти 4 года назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-5p65-6rwr-377w

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5mxj-8vqf-cpf9

почти 4 года назад

An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-5mpx-m64g-xxgq

почти 4 года назад

GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).

EPSS: Низкий
github логотип

GHSA-5mm2-786g-8qwh

почти 4 года назад

A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

EPSS: Низкий
github логотип

GHSA-5mjv-86c4-mprj

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-5mcq-mg28-vj82

почти 4 года назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

EPSS: Низкий
github логотип

GHSA-5m57-mhq7-6vhf

почти 4 года назад

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

EPSS: Низкий
github логотип

GHSA-5jjr-96vg-hj88

почти 4 года назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

EPSS: Низкий
github логотип

GHSA-5jj4-fh62-42vp

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5qwh-g35c-5mmm

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

CVSS3: 3
0%
Низкий
больше 1 года назад
github логотип
GHSA-5qpg-r237-3pm4

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5qhc-78h9-5m5x

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

CVSS3: 3.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-5q5j-r39w-wc64

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-5px4-prjg-wgwv

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5prc-f4c3-qjpv

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions.

CVSS3: 3.5
0%
Низкий
19 дней назад
github логотип
GHSA-5pqm-4gpg-63j8

An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-5phj-qv74-pv4w

Missing permission check in Jenkins GitLab Plugin

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-5p95-g2w7-2rfh

Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

0%
Низкий
почти 4 года назад
github логотип
GHSA-5p8h-m559-wpw7

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5p89-g2g5-4687

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5p65-6rwr-377w

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-5mxj-8vqf-cpf9

An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5mpx-m64g-xxgq

GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).

0%
Низкий
почти 4 года назад
github логотип
GHSA-5mm2-786g-8qwh

A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

0%
Низкий
почти 4 года назад
github логотип
GHSA-5mjv-86c4-mprj

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-5mcq-mg28-vj82

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5m57-mhq7-6vhf

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5jjr-96vg-hj88

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

0%
Низкий
почти 4 года назад
github логотип
GHSA-5jj4-fh62-42vp

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.

CVSS3: 5.3
1%
Низкий
около 3 лет назад

Уязвимостей на страницу