Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 531

Количество 5 531

github логотип

GHSA-4h46-82xr-4j7x

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-4h2m-723p-2ww2

почти 4 года назад

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4gm2-v7j4-74p8

почти 4 года назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-4g7q-7v9w-3x8m

почти 2 года назад

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-4g69-rp74-jj24

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-4fv6-2265-mqxm

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fr5-6ccq-75w2

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4fff-jcr9-g646

почти 4 года назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4ff8-x6j5-88r4

почти 4 года назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

EPSS: Низкий
github логотип

GHSA-4cqm-q6hh-xmp9

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

EPSS: Низкий
github логотип

GHSA-4cj3-9m97-2989

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4ccf-v4wp-c858

почти 4 года назад

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

EPSS: Низкий
github логотип

GHSA-4c45-wmm4-4hq2

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-49wm-7m27-7m24

почти 4 года назад

GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-49rg-2gmx-qjmr

почти 4 года назад

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

EPSS: Средний
github логотип

GHSA-49pq-xj6m-j384

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-48jv-2rrr-w2f7

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-48fw-3qmc-rmp7

почти 4 года назад

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

EPSS: Низкий
github логотип

GHSA-4839-fmx8-4hrv

почти 4 года назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.

EPSS: Низкий
github логотип

GHSA-47xx-c7pc-hm29

почти 4 года назад

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4h46-82xr-4j7x

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-4h2m-723p-2ww2

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-4gm2-v7j4-74p8

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVSS3: 9.8
77%
Высокий
почти 4 года назад
github логотип
GHSA-4g7q-7v9w-3x8m

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-4g69-rp74-jj24

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-4fv6-2265-mqxm

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-4fr5-6ccq-75w2

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4fff-jcr9-g646

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-4ff8-x6j5-88r4

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4cqm-q6hh-xmp9

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4cj3-9m97-2989

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-4ccf-v4wp-c858

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4c45-wmm4-4hq2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

CVSS3: 6.5
9%
Низкий
почти 4 года назад
github логотип
GHSA-49wm-7m27-7m24

GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-49rg-2gmx-qjmr

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

12%
Средний
почти 4 года назад
github логотип
GHSA-49pq-xj6m-j384

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS3: 9.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-48jv-2rrr-w2f7

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-48fw-3qmc-rmp7

Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4839-fmx8-4hrv

For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-47xx-c7pc-hm29

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу