Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-3f26-542m-36hv

больше 3 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

EPSS: Низкий
github логотип

GHSA-3cw2-66px-r367

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cq3-cj5m-hm72

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing malicious JSON payloads.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3cmp-fvxf-q58q

больше 3 лет назад

GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cm3-9ccj-7mvq

около 4 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

EPSS: Низкий
github логотип

GHSA-3cjm-23gg-86mm

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3cgp-mpf6-c8vw

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cg7-x7vx-225c

11 месяцев назад

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3c89-47f8-w5c6

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3c74-ghrj-c3gp

больше 3 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3c57-hg33-rhrp

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-39rg-m8qv-7ff5

больше 3 лет назад

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

EPSS: Низкий
github логотип

GHSA-39m5-rg2v-54h9

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-397r-9xj2-fj79

больше 3 лет назад

An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment.

EPSS: Низкий
github логотип

GHSA-38q5-vqf6-27rf

5 месяцев назад

A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38f2-vcgr-hqxh

больше 1 года назад

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3735-4fjf-vq4q

9 дней назад

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-36p7-jqv6-r5mj

больше 3 лет назад

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36f4-j6rh-2hw2

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-3652-xvjx-j36p

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f26-542m-36hv

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cw2-66px-r367

An issue has been discovered in GitLab affecting all versions starting from 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cq3-cj5m-hm72

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing malicious JSON payloads.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3cmp-fvxf-q58q

GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cm3-9ccj-7mvq

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

0%
Низкий
около 4 лет назад
github логотип
GHSA-3cjm-23gg-86mm

An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cgp-mpf6-c8vw

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cg7-x7vx-225c

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3c89-47f8-w5c6

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3c74-ghrj-c3gp

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c57-hg33-rhrp

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.

CVSS3: 5
0%
Низкий
6 месяцев назад
github логотип
GHSA-39rg-m8qv-7ff5

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-39m5-rg2v-54h9

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

CVSS3: 2
0%
Низкий
3 месяца назад
github логотип
GHSA-397r-9xj2-fj79

An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38q5-vqf6-27rf

A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-38f2-vcgr-hqxh

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3735-4fjf-vq4q

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

CVSS3: 3.1
0%
Низкий
9 дней назад
github логотип
GHSA-36p7-jqv6-r5mj

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36f4-j6rh-2hw2

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3652-xvjx-j36p

An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces.

CVSS3: 4.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу