Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 995

Количество 5 995

github логотип

GHSA-w555-m56g-r558

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w4wr-jxpf-c7j5

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w4fh-mw73-5c5w

больше 3 лет назад

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w487-9r9p-6p96

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w44h-qxhv-wqww

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w3fw-23jp-3855

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w37f-8cwf-64g5

больше 4 лет назад

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w2rm-x498-v7f9

больше 2 лет назад

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-w2rf-v2fh-5mjh

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-w2m4-xx67-836j

11 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w2j6-r4xj-rjcj

9 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-w2gf-3qqp-3r4x

больше 4 лет назад

An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.

EPSS: Низкий
github логотип

GHSA-w2fx-qxhw-34qh

больше 4 лет назад

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-w2fr-4vgx-vq96

больше 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-vxw5-rxj4-h92f

больше 1 года назад

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vxf7-7c9g-m3x8

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vx93-hvpm-489j

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

EPSS: Низкий
github логотип

GHSA-vx8w-6r69-h5fv

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vx7c-2qqj-4773

больше 4 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

EPSS: Низкий
github логотип

GHSA-vx5g-jgx3-6mx9

больше 4 лет назад

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-w555-m56g-r558

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-w4wr-jxpf-c7j5

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpoint.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-w4fh-mw73-5c5w

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-w487-9r9p-6p96

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-w44h-qxhv-wqww

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-w3fw-23jp-3855

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-w37f-8cwf-64g5

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-w2rm-x498-v7f9

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-w2rf-v2fh-5mjh

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

CVSS3: 3.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-w2m4-xx67-836j

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

CVSS3: 7.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-w2j6-r4xj-rjcj

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-w2gf-3qqp-3r4x

An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-w2fx-qxhw-34qh

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-w2fr-4vgx-vq96

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-vxw5-rxj4-h92f

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-vxf7-7c9g-m3x8

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-vx93-hvpm-489j

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vx8w-6r69-h5fv

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-vx7c-2qqj-4773

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vx5g-jgx3-6mx9

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу