Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-4hcg-rvwm-x96m

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4h9q-f95v-pf5f

больше 3 лет назад

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

EPSS: Низкий
github логотип

GHSA-4h46-82xr-4j7x

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-4h2m-723p-2ww2

больше 3 лет назад

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4gm2-v7j4-74p8

больше 3 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

EPSS: Средний
github логотип

GHSA-4g7q-7v9w-3x8m

больше 1 года назад

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-4g69-rp74-jj24

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-4fv6-2265-mqxm

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fr5-6ccq-75w2

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4fff-jcr9-g646

почти 4 года назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4ff8-x6j5-88r4

больше 3 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

EPSS: Низкий
github логотип

GHSA-4cqm-q6hh-xmp9

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

EPSS: Низкий
github логотип

GHSA-4cj3-9m97-2989

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4ccf-v4wp-c858

больше 3 лет назад

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

EPSS: Низкий
github логотип

GHSA-4c45-wmm4-4hq2

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-49wm-7m27-7m24

больше 3 лет назад

GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-49rg-2gmx-qjmr

больше 3 лет назад

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

EPSS: Средний
github логотип

GHSA-49pq-xj6m-j384

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-48jv-2rrr-w2f7

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-48fw-3qmc-rmp7

больше 3 лет назад

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4hcg-rvwm-x96m

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4h9q-f95v-pf5f

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4h46-82xr-4j7x

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-4h2m-723p-2ww2

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4gm2-v7j4-74p8

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

60%
Средний
больше 3 лет назад
github логотип
GHSA-4g7q-7v9w-3x8m

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4g69-rp74-jj24

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-4fv6-2265-mqxm

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4fr5-6ccq-75w2

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4fff-jcr9-g646

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-4ff8-x6j5-88r4

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4cqm-q6hh-xmp9

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4cj3-9m97-2989

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4ccf-v4wp-c858

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4c45-wmm4-4hq2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

CVSS3: 6.5
9%
Низкий
больше 3 лет назад
github логотип
GHSA-49wm-7m27-7m24

GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-49rg-2gmx-qjmr

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

14%
Средний
больше 3 лет назад
github логотип
GHSA-49pq-xj6m-j384

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-48jv-2rrr-w2f7

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-48fw-3qmc-rmp7

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу