Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2025-4979

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2025-4979

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2025-4976

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-4976

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-4976

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-4972

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2025-4972

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2025-4700

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-4700

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-4700

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-4439

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2025-4439

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2025-4439

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2025-4278

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-4278

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-4278

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-4225

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-4225

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-4097

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-4097

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-4979

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

CVSS3: 4.9
0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-4979

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.9
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-4976

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-4976

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-4976

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 4.3
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-4972

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.

CVSS3: 2.7
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-4972

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 2.7
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2025-4700

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

CVSS3: 8.7
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-4700

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

CVSS3: 8.7
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-4700

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2025-4439

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

CVSS3: 7.7
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-4439

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

CVSS3: 7.7
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-4439

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.7
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2025-4278

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-4278

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-4278

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-4225

An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-4225

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-4097

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-4097

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

CVSS3: 6.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу