Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-2cvh-3hhx-675v

около 1 года назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cpf-j432-984q

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2cg5-9vjw-w6vg

11 месяцев назад

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2cf2-299c-gg46

больше 3 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2c6m-54c4-x2fg

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2. It was possible for a guest to read the source code of a private project by using group templates.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29qv-5fpp-cv72

больше 3 лет назад

An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.

EPSS: Низкий
github логотип

GHSA-29hm-v8p9-7mcg

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-294h-9fqc-xfq7

больше 3 лет назад

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28w7-9227-5wcm

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-28w5-8wm6-h27m

больше 3 лет назад

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28m9-57g2-hv97

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28j9-fq4c-qrqg

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's CI/CD pipeline editor could allow for denial of service attacks through maliciously crafted configuration files.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-289v-j7vm-cm7q

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

EPSS: Низкий
github логотип

GHSA-2862-gpw6-r482

11 месяцев назад

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2834-55v8-f2v4

почти 4 года назад

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2826-9vpv-crx3

больше 3 лет назад

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27v4-8jv4-3cp6

больше 3 лет назад

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

EPSS: Низкий
github логотип

GHSA-27r2-6rqh-xrg8

почти 2 года назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-27p2-q4g5-wxm8

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.

EPSS: Низкий
github логотип

GHSA-27jm-6pj2-8w7g

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cvh-3hhx-675v

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2cpf-j432-984q

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2cg5-9vjw-w6vg

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2cf2-299c-gg46

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c6m-54c4-x2fg

An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2. It was possible for a guest to read the source code of a private project by using group templates.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-29qv-5fpp-cv72

An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29hm-v8p9-7mcg

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-294h-9fqc-xfq7

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28w7-9227-5wcm

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

CVSS3: 2.7
0%
Низкий
4 месяца назад
github логотип
GHSA-28w5-8wm6-h27m

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28m9-57g2-hv97

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-28j9-fq4c-qrqg

An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's CI/CD pipeline editor could allow for denial of service attacks through maliciously crafted configuration files.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-289v-j7vm-cm7q

A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2862-gpw6-r482

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-2834-55v8-f2v4

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-2826-9vpv-crx3

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v4-8jv4-3cp6

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27r2-6rqh-xrg8

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-27p2-q4g5-wxm8

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27jm-6pj2-8w7g

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

CVSS3: 8.7
0%
Низкий
8 месяцев назад

Уязвимостей на страницу