Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-vrcq-g4r8-v287

почти 4 года назад

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vr5w-hwpc-cjqr

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-vqfr-3pj8-54gm

почти 4 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-vpx5-hq6c-gr3m

почти 4 года назад

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-vp89-phvm-4cjr

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.

EPSS: Низкий
github логотип

GHSA-vp64-6mxr-66qc

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-vp53-cwf4-9466

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-vm62-p48h-5h9h

почти 4 года назад

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

EPSS: Низкий
github логотип

GHSA-vjxq-fxvh-23vc

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).

EPSS: Низкий
github логотип

GHSA-vjph-qj4m-f5g8

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vj39-w82r-gvcp

почти 4 года назад

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vj2x-h34v-wpwp

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vgp2-3hxm-6x85

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVSS3: 10
EPSS: Критический
github логотип

GHSA-vgcv-58jw-xrwf

почти 4 года назад

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

EPSS: Низкий
github логотип

GHSA-vg95-5p98-2464

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vg8q-6f88-6vrh

почти 4 года назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vg85-gmcc-wrqw

больше 1 года назад

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-vfph-fvw4-j4xp

больше 1 года назад

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-vf84-rvwc-7mx6

почти 4 года назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-vcvr-9mwv-w2g3

8 месяцев назад

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vrcq-g4r8-v287

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-vr5w-hwpc-cjqr

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-vqfr-3pj8-54gm

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

0%
Низкий
почти 4 года назад
github логотип
GHSA-vpx5-hq6c-gr3m

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-vp89-phvm-4cjr

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.

0%
Низкий
почти 4 года назад
github логотип
GHSA-vp64-6mxr-66qc

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-vp53-cwf4-9466

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-vm62-p48h-5h9h

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

0%
Низкий
почти 4 года назад
github логотип
GHSA-vjxq-fxvh-23vc

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).

0%
Низкий
почти 4 года назад
github логотип
GHSA-vjph-qj4m-f5g8

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-vj39-w82r-gvcp

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-vj2x-h34v-wpwp

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-vgp2-3hxm-6x85

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVSS3: 10
94%
Критический
почти 4 года назад
github логотип
GHSA-vgcv-58jw-xrwf

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

0%
Низкий
почти 4 года назад
github логотип
GHSA-vg95-5p98-2464

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-vg8q-6f88-6vrh

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-vg85-gmcc-wrqw

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

CVSS3: 2.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-vfph-fvw4-j4xp

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-vf84-rvwc-7mx6

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-vcvr-9mwv-w2g3

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

CVSS3: 3.1
0%
Низкий
8 месяцев назад

Уязвимостей на страницу