Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 531

Количество 5 531

github логотип

GHSA-2px3-3vqh-4m6q

почти 4 года назад

In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query

EPSS: Низкий
github логотип

GHSA-2pc6-768q-99h7

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

EPSS: Низкий
github логотип

GHSA-2p9w-5q3p-g7cv

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2p9m-5cj9-r9pf

около 4 лет назад

In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2p89-vr82-6vw5

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

EPSS: Низкий
github логотип

GHSA-2mw4-5fh2-j3wh

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mp7-775v-6hf6

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2mm8-x5g7-wf73

почти 4 года назад

An Improper Access Control vulnerability in the GraphQL API in GitLab CE/EE since version 13.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2m6q-rj94-6952

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-2jwx-73fx-pwrv

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2jv7-gvqw-mxm4

20 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the group import process under certain circumstances.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2jq2-4fqx-jx67

почти 4 года назад

Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jhc-hf67-8vgx

6 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in GraphQL request processing.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jcr-4r89-72r6

почти 4 года назад

GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.

EPSS: Низкий
github логотип

GHSA-2j7r-vr72-m9vf

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2j76-jpwv-99mp

почти 4 года назад

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

EPSS: Низкий
github логотип

GHSA-2hjx-qmr7-gg4r

около 4 лет назад

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

EPSS: Низкий
github логотип

GHSA-2hgm-r8rh-g5xg

почти 4 года назад

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

EPSS: Низкий
github логотип

GHSA-2h7w-85g4-9cx4

почти 4 года назад

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2h39-hw8g-2q24

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2px3-3vqh-4m6q

In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query

0%
Низкий
почти 4 года назад
github логотип
GHSA-2pc6-768q-99h7

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2p9w-5q3p-g7cv

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
2%
Низкий
почти 3 года назад
github логотип
GHSA-2p9m-5cj9-r9pf

In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2p89-vr82-6vw5

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

0%
Низкий
почти 4 года назад
github логотип
GHSA-2mw4-5fh2-j3wh

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2mp7-775v-6hf6

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mm8-x5g7-wf73

An Improper Access Control vulnerability in the GraphQL API in GitLab CE/EE since version 13.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2m6q-rj94-6952

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVSS3: 5.7
4%
Низкий
почти 3 года назад
github логотип
GHSA-2jwx-73fx-pwrv

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
0%
Низкий
4 месяца назад
github логотип
GHSA-2jv7-gvqw-mxm4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the group import process under certain circumstances.

CVSS3: 4.3
0%
Низкий
20 дней назад
github логотип
GHSA-2jq2-4fqx-jx67

Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2jhc-hf67-8vgx

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in GraphQL request processing.

CVSS3: 7.5
0%
Низкий
6 дней назад
github логотип
GHSA-2jcr-4r89-72r6

GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2j7r-vr72-m9vf

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2j76-jpwv-99mp

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hjx-qmr7-gg4r

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

0%
Низкий
около 4 лет назад
github логотип
GHSA-2hgm-r8rh-g5xg

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

1%
Низкий
почти 4 года назад
github логотип
GHSA-2h7w-85g4-9cx4

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2h39-hw8g-2q24

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.

CVSS3: 5.4
0%
Низкий
почти 4 года назад

Уязвимостей на страницу