Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 706

Количество 4 706

github логотип

GHSA-v9g5-36x8-7xmx

3 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-v95j-qhvj-8v9x

около 3 лет назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

EPSS: Низкий
github логотип

GHSA-v92j-h587-3vv3

почти 3 года назад

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v84c-53c6-xmmp

8 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v7wh-rwr5-886x

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v6xp-h7ww-6xqf

8 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-v6wj-hx5h-fhwp

около 3 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v68j-qxmr-9486

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v64g-f7qf-63xm

больше 1 года назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v648-cf9r-9m29

около 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v4qw-4358-7wh4

больше 3 лет назад

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

EPSS: Низкий
github логотип

GHSA-v3p6-8992-mc58

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-v3j6-jv37-286j

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v2jw-9cf3-v6vg

около 3 лет назад

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.

EPSS: Низкий
github логотип

GHSA-v2gw-42rh-8v5g

почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-v254-7f59-gpqj

около 3 лет назад

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-v253-xqc5-h554

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

EPSS: Низкий
github логотип

GHSA-rxh8-jh3g-ccqq

около 3 лет назад

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rxf6-f2p5-q27m

около 3 лет назад

An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.

EPSS: Низкий
github логотип

GHSA-rww2-m274-8f9v

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-v9g5-36x8-7xmx

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
0%
Низкий
3 месяца назад
github логотип
GHSA-v95j-qhvj-8v9x

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

0%
Низкий
около 3 лет назад
github логотип
GHSA-v92j-h587-3vv3

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-v84c-53c6-xmmp

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-v7wh-rwr5-886x

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-v6xp-h7ww-6xqf

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-v6wj-hx5h-fhwp

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-v68j-qxmr-9486

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-v64g-f7qf-63xm

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-v648-cf9r-9m29

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-v4qw-4358-7wh4

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

0%
Низкий
больше 3 лет назад
github логотип
GHSA-v3p6-8992-mc58

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).

CVSS3: 3.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-v3j6-jv37-286j

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.

CVSS3: 6.5
6%
Низкий
около 1 года назад
github логотип
GHSA-v2jw-9cf3-v6vg

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.

0%
Низкий
около 3 лет назад
github логотип
GHSA-v2gw-42rh-8v5g

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.

CVSS3: 5
0%
Низкий
почти 2 года назад
github логотип
GHSA-v254-7f59-gpqj

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-v253-xqc5-h554

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

0%
Низкий
около 3 лет назад
github логотип
GHSA-rxh8-jh3g-ccqq

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

CVSS3: 8.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-rxf6-f2p5-q27m

An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.

0%
Низкий
около 3 лет назад
github логотип
GHSA-rww2-m274-8f9v

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

CVSS3: 8.7
1%
Низкий
7 месяцев назад

Уязвимостей на страницу