Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

github логотип

GHSA-22mg-qg4r-wh4q

больше 3 лет назад

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22hj-9cx7-p2hw

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2298-j2fr-472h

больше 2 лет назад

A denial of service issue was discovered in GitLab CE/EE affecting all versions starting from 13.2.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2 which allows an attacker to cause high resource consumption using malicious test report artifacts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2244-rvc8-pc38

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control,

EPSS: Низкий
ubuntu логотип

CVE-2026-1751

9 дней назад

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2026-1751

9 дней назад

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2026-1751

9 дней назад

A vulnerability has been discovered in GitLab CE/EE affecting all vers ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2026-1102

20 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-1102

20 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-1102

20 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-0723

20 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-0723

20 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2026-0723

20 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2025-9958

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2025-9958

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2025-9825

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2025-9825

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2025-9825

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2025-9642

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-9642

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22mg-qg4r-wh4q

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22hj-9cx7-p2hw

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS3: 7.5
53%
Средний
около 4 лет назад
github логотип
GHSA-2298-j2fr-472h

A denial of service issue was discovered in GitLab CE/EE affecting all versions starting from 13.2.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2 which allows an attacker to cause high resource consumption using malicious test report artifacts.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2244-rvc8-pc38

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control,

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2026-1751

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

CVSS3: 3.1
0%
Низкий
9 дней назад
nvd логотип
CVE-2026-1751

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

CVSS3: 3.1
0%
Низкий
9 дней назад
debian логотип
CVE-2026-1751

A vulnerability has been discovered in GitLab CE/EE affecting all vers ...

CVSS3: 3.1
0%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-1102

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.

CVSS3: 5.3
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-1102

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.

CVSS3: 5.3
0%
Низкий
20 дней назад
debian логотип
CVE-2026-1102

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 5.3
0%
Низкий
20 дней назад
ubuntu логотип
CVE-2026-0723

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.

CVSS3: 7.4
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-0723

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.

CVSS3: 7.4
0%
Низкий
20 дней назад
debian логотип
CVE-2026-0723

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.4
0%
Низкий
20 дней назад
nvd логотип
CVE-2025-9958

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

CVSS3: 7.7
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-9958

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.7
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-9825

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-9825

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-9825

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-9642

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

CVSS3: 8.7
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-9642

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
0%
Низкий
5 месяцев назад

Уязвимостей на страницу