Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 531

Количество 5 531

github логотип

GHSA-2xmx-mqmp-xw34

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2xjp-r9f7-cm2x

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-2xj7-mfw6-mfvm

почти 4 года назад

GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2x3p-pww2-fg9r

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2wrv-52w9-gffw

почти 4 года назад

When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2wm6-w8f9-5vf4

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.

EPSS: Низкий
github логотип

GHSA-2wh2-fff9-4m63

больше 2 лет назад

An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-2w7q-mj4w-9cm2

около 2 лет назад

An improper access control vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2w2f-9xfg-pc7q

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vqg-gr4m-v458

почти 4 года назад

A stored Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2v4g-65gf-w58f

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v36-29xm-jp89

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rf4-rj3g-f4pj

почти 4 года назад

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2r7r-6rh2-7qc9

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2r57-8pgj-h27p

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2qx5-mv7p-q62v

почти 4 года назад

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

EPSS: Низкий
github логотип

GHSA-2qvv-wf53-7c44

почти 4 года назад

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

EPSS: Низкий
github логотип

GHSA-2qmw-465m-g262

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

EPSS: Низкий
github логотип

GHSA-2qhw-5384-m8g2

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2q5x-gf4q-9227

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xmx-mqmp-xw34

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2xjp-r9f7-cm2x

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
0%
Низкий
около 1 года назад
github логотип
GHSA-2xj7-mfw6-mfvm

GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2x3p-pww2-fg9r

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2wrv-52w9-gffw

When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs

CVSS3: 7.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2wm6-w8f9-5vf4

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wh2-fff9-4m63

An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.

CVSS3: 3.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2w7q-mj4w-9cm2

An improper access control vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-2w2f-9xfg-pc7q

An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2vqg-gr4m-v458

A stored Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2v4g-65gf-w58f

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2v36-29xm-jp89

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2rf4-rj3g-f4pj

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2r7r-6rh2-7qc9

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

CVSS3: 7.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-2r57-8pgj-h27p

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2qx5-mv7p-q62v

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2qvv-wf53-7c44

A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2qmw-465m-g262

An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2qhw-5384-m8g2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2q5x-gf4q-9227

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу