Количество 4 670
Количество 4 670
GHSA-vrcq-g4r8-v287
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
GHSA-vr5w-hwpc-cjqr
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.
GHSA-vqfr-3pj8-54gm
An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
GHSA-vpx5-hq6c-gr3m
GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.
GHSA-vp89-phvm-4cjr
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.
GHSA-vp53-cwf4-9466
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.
GHSA-vm62-p48h-5h9h
A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.
GHSA-vjxq-fxvh-23vc
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).
GHSA-vjph-qj4m-f5g8
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions
GHSA-vj39-w82r-gvcp
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
GHSA-vj2x-h34v-wpwp
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.
GHSA-vgp2-3hxm-6x85
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
GHSA-vgcv-58jw-xrwf
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
GHSA-vg95-5p98-2464
An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.
GHSA-vg8q-6f88-6vrh
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.
GHSA-vg85-gmcc-wrqw
Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."
GHSA-vfph-fvw4-j4xp
An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.
GHSA-vf84-rvwc-7mx6
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.
GHSA-v9r7-fcc3-gg2v
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.
GHSA-v9g5-36x8-7xmx
An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-vrcq-g4r8-v287 An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-vr5w-hwpc-cjqr An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded. | CVSS3: 5.7 | 0% Низкий | 12 месяцев назад | |
GHSA-vqfr-3pj8-54gm An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2. | 0% Низкий | около 3 лет назад | ||
GHSA-vpx5-hq6c-gr3m GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control. | 0% Низкий | около 3 лет назад | ||
GHSA-vp89-phvm-4cjr An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch. | 0% Низкий | около 3 лет назад | ||
GHSA-vp53-cwf4-9466 An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control. | 0% Низкий | около 3 лет назад | ||
GHSA-vm62-p48h-5h9h A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin. | 0% Низкий | около 3 лет назад | ||
GHSA-vjxq-fxvh-23vc An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2). | 0% Низкий | около 3 лет назад | ||
GHSA-vjph-qj4m-f5g8 An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-vj39-w82r-gvcp In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-vj2x-h34v-wpwp An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-vgp2-3hxm-6x85 An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. | CVSS3: 10 | 94% Критический | около 3 лет назад | |
GHSA-vgcv-58jw-xrwf In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. | 0% Низкий | около 3 лет назад | ||
GHSA-vg95-5p98-2464 An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-vg8q-6f88-6vrh GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-vg85-gmcc-wrqw Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project." | CVSS3: 2.6 | 0% Низкий | 10 месяцев назад | |
GHSA-vfph-fvw4-j4xp An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting. | CVSS3: 5.5 | 0% Низкий | 10 месяцев назад | |
GHSA-vf84-rvwc-7mx6 An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control. | 0% Низкий | около 3 лет назад | ||
GHSA-v9r7-fcc3-gg2v An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-v9g5-36x8-7xmx An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements. | CVSS3: 4.6 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу