Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-3rpg-jfvw-x748

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.

EPSS: Низкий
github логотип

GHSA-3rm3-2566-pgwv

больше 3 лет назад

A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r2f-rpgw-83gm

больше 3 лет назад

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

EPSS: Низкий
github логотип

GHSA-3r2c-p78w-vg88

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3qvq-h337-wprv

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qvh-rmmw-6m99

больше 3 лет назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issue reference number tooltip.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p78-2x5r-gjpp

больше 3 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mp9-x5q5-63w3

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m8p-28cp-6cg5

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3jr7-57xj-6hhm

больше 3 лет назад

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

EPSS: Низкий
github логотип

GHSA-3jmg-94rq-h4hm

больше 3 лет назад

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

EPSS: Низкий
github логотип

GHSA-3jj9-4wwv-fwwp

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hmc-2fvj-7wmx

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3hm6-rvrr-hc6r

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-3h4g-986f-gvf8

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

EPSS: Низкий
github логотип

GHSA-3gvc-g7j2-9532

больше 3 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-3gcx-c67c-32vj

больше 3 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g66-9x43-7v6m

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3frq-wfvj-c4fp

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Missing Authorization.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f4w-jvcp-5g28

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rpg-jfvw-x748

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rm3-2566-pgwv

A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2f-rpgw-83gm

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2c-p78w-vg88

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3qvq-h337-wprv

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3qvh-rmmw-6m99

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issue reference number tooltip.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p78-2x5r-gjpp

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mp9-x5q5-63w3

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3m8p-28cp-6cg5

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jr7-57xj-6hhm

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jmg-94rq-h4hm

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jj9-4wwv-fwwp

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3hmc-2fvj-7wmx

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-3hm6-rvrr-hc6r

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
39%
Средний
около 2 лет назад
github логотип
GHSA-3h4g-986f-gvf8

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gvc-g7j2-9532

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcx-c67c-32vj

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g66-9x43-7v6m

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3frq-wfvj-c4fp

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Missing Authorization.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f4w-jvcp-5g28

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу