Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 531

Количество 5 531

github логотип

GHSA-3r2f-rpgw-83gm

почти 4 года назад

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

EPSS: Низкий
github логотип

GHSA-3r2c-p78w-vg88

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3qvq-h337-wprv

9 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qvh-rmmw-6m99

почти 4 года назад

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issue reference number tooltip.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3qcv-5pqj-c2h7

6 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3p78-2x5r-gjpp

почти 4 года назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mp9-x5q5-63w3

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m8p-28cp-6cg5

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3jr7-57xj-6hhm

почти 4 года назад

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

EPSS: Низкий
github логотип

GHSA-3jmg-94rq-h4hm

почти 4 года назад

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

EPSS: Низкий
github логотип

GHSA-3jj9-4wwv-fwwp

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hmc-2fvj-7wmx

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3hm6-rvrr-hc6r

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-3h4g-986f-gvf8

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

EPSS: Низкий
github логотип

GHSA-3gvc-g7j2-9532

почти 4 года назад

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-3gcx-c67c-32vj

почти 4 года назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g66-9x43-7v6m

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3frq-wfvj-c4fp

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Missing Authorization.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f68-rg4r-xc3q

6 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f4w-jvcp-5g28

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3r2f-rpgw-83gm

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

2%
Низкий
почти 4 года назад
github логотип
GHSA-3r2c-p78w-vg88

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
0%
Низкий
3 месяца назад
github логотип
GHSA-3qvq-h337-wprv

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3qvh-rmmw-6m99

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issue reference number tooltip.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3qcv-5pqj-c2h7

GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.

CVSS3: 7.7
0%
Низкий
6 дней назад
github логотип
GHSA-3p78-2x5r-gjpp

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3mp9-x5q5-63w3

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3m8p-28cp-6cg5

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jr7-57xj-6hhm

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jmg-94rq-h4hm

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jj9-4wwv-fwwp

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3hmc-2fvj-7wmx

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-3hm6-rvrr-hc6r

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
41%
Средний
около 2 лет назад
github логотип
GHSA-3h4g-986f-gvf8

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3gvc-g7j2-9532

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3gcx-c67c-32vj

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3g66-9x43-7v6m

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3frq-wfvj-c4fp

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Missing Authorization.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3f68-rg4r-xc3q

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.

CVSS3: 6.5
0%
Низкий
6 дней назад
github логотип
GHSA-3f4w-jvcp-5g28

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу