Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 531

Количество 5 531

github логотип

GHSA-4v6w-vxg7-j28q

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-4v46-g8g9-868m

почти 4 года назад

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

EPSS: Низкий
github логотип

GHSA-4v3f-ffrw-xcx6

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rph-jr9g-hq9q

почти 4 года назад

GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4rmw-pmhj-w226

почти 4 года назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.

EPSS: Низкий
github логотип

GHSA-4rf9-gv7f-cc74

около 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4qc4-p4r5-q24g

почти 4 года назад

Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4mw5-77qf-jmw4

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4mm8-64px-38hf

почти 4 года назад

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

EPSS: Низкий
github логотип

GHSA-4mcw-rvpf-x558

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4m8h-w9w3-cp2v

около 3 лет назад

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4m4w-7ph3-mcfg

10 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4jm7-cxrm-w3f4

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 2 of 5).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4jhx-xj9w-gw72

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4j77-rj27-2wxq

6 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge requests in other projects due to improper access control during cross-repository operations.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4j42-wq8q-c389

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-4hq6-hm84-9r6r

почти 4 года назад

GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4hh9-ph5p-g4m9

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.

EPSS: Низкий
github логотип

GHSA-4hcg-rvwm-x96m

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4h9q-f95v-pf5f

почти 4 года назад

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v6w-vxg7-j28q

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v46-g8g9-868m

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4v3f-ffrw-xcx6

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4rph-jr9g-hq9q

GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-4rmw-pmhj-w226

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4rf9-gv7f-cc74

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4qc4-p4r5-q24g

Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-4mw5-77qf-jmw4

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-4mm8-64px-38hf

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4mcw-rvpf-x558

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.

CVSS3: 7.7
0%
Низкий
4 месяца назад
github логотип
GHSA-4m8h-w9w3-cp2v

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-4m4w-7ph3-mcfg

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 3.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-4jm7-cxrm-w3f4

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 2 of 5).

CVSS3: 5.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-4jhx-xj9w-gw72

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4j77-rj27-2wxq

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge requests in other projects due to improper access control during cross-repository operations.

CVSS3: 4.3
0%
Низкий
6 дней назад
github логотип
GHSA-4j42-wq8q-c389

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.

CVSS3: 10
0%
Низкий
почти 4 года назад
github логотип
GHSA-4hq6-hm84-9r6r

GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-4hh9-ph5p-g4m9

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4hcg-rvwm-x96m

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4h9q-f95v-pf5f

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу