Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2025-4097

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-3950

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-3950

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2025-3950

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-3601

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-3601

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-3396

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-3396

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-3279

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-3279

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-3279

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-3111

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-3111

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-3111

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-2938

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-2938

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-2938

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2025-2937

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-2937

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-2937

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2025-4097

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2025-3950

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-3950

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

CVSS3: 3.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-3950

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-3601

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-3601

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-3396

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-3396

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 4.3
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2025-3279

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-3279

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-3279

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-3111

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVSS3: 6.5
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-3111

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVSS3: 6.5
0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-3111

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-2938

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-2938

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-2938

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.1
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-2937

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-2937

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-2937

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу