Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 995

Количество 5 995

github логотип

GHSA-vx2h-m34g-ggpg

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-vwxf-55xh-p3xf

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-vwj5-wr4r-cq36

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-vvcp-5v5p-8jhc

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vrvm-qc4x-35pw

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-vrqc-vwgr-qqp5

больше 4 лет назад

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-vrgc-533g-v7r4

больше 4 лет назад

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vrcq-g4r8-v287

больше 4 лет назад

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vr5w-hwpc-cjqr

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-vqfr-3pj8-54gm

больше 4 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-vpx5-hq6c-gr3m

больше 4 лет назад

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-vp89-phvm-4cjr

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.

EPSS: Низкий
github логотип

GHSA-vp64-6mxr-66qc

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-vp53-cwf4-9466

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-vm62-p48h-5h9h

больше 4 лет назад

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

EPSS: Низкий
github логотип

GHSA-vjxq-fxvh-23vc

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).

EPSS: Низкий
github логотип

GHSA-vjph-qj4m-f5g8

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vjff-3wcf-gwp3

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vj39-w82r-gvcp

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vj2x-h34v-wpwp

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vx2h-m34g-ggpg

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 4.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-vwxf-55xh-p3xf

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).

CVSS3: 3.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-vwj5-wr4r-cq36

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-vvcp-5v5p-8jhc

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-vrvm-qc4x-35pw

An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs.

CVSS3: 3.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-vrqc-vwgr-qqp5

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.8
76%
Высокий
больше 4 лет назад
github логотип
GHSA-vrgc-533g-v7r4

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-vrcq-g4r8-v287

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-vr5w-hwpc-cjqr

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-vqfr-3pj8-54gm

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vpx5-hq6c-gr3m

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vp89-phvm-4cjr

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vp64-6mxr-66qc

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

CVSS3: 8.7
0%
Низкий
около 1 года назад
github логотип
GHSA-vp53-cwf4-9466

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vm62-p48h-5h9h

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vjxq-fxvh-23vc

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vjph-qj4m-f5g8

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-vjff-3wcf-gwp3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
github логотип
GHSA-vj39-w82r-gvcp

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-vj2x-h34v-wpwp

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 4.3
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу