Количество 5 336
Количество 5 336
CVE-2025-2443
An issue has been discovered in GitLab EE that allows for cross-site-s ...
CVE-2025-24397
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.
CVE-2025-2408
An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.
CVE-2025-2408
An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.
CVE-2025-2408
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2025-2256
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.
CVE-2025-2256
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2025-2255
An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.
CVE-2025-2255
An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.
CVE-2025-2255
An issue has been discovered in Gitlab EE/CE for AppSec affecting all ...
CVE-2025-2254
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.
CVE-2025-2254
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.
CVE-2025-2254
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2025-2246
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
CVE-2025-2246
An issue has been discovered in GitLab CE/EE affecting all versions be ...
CVE-2025-2242
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.
CVE-2025-2242
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.
CVE-2025-2242
An improper access control vulnerability in GitLab CE/EE affecting all ...
CVE-2025-2045
Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.
CVE-2025-2045
Improper authorization in GitLab EE affecting all versions from 17.7 p ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-2443 An issue has been discovered in GitLab EE that allows for cross-site-s ... | CVSS3: 8.7 | 0% Низкий | 8 месяцев назад | |
CVE-2025-24397 An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
CVE-2025-2408 An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-2408 An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-2408 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-2256 An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2025-2256 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2025-2255 An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec. | CVSS3: 8.7 | 0% Низкий | 11 месяцев назад | |
CVE-2025-2255 An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec. | CVSS3: 8.7 | 0% Низкий | 11 месяцев назад | |
CVE-2025-2255 An issue has been discovered in Gitlab EE/CE for AppSec affecting all ... | CVSS3: 8.7 | 0% Низкий | 11 месяцев назад | |
CVE-2025-2254 An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks. | CVSS3: 8.7 | 0% Низкий | 8 месяцев назад | |
CVE-2025-2254 An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks. | CVSS3: 8.7 | 0% Низкий | 8 месяцев назад | |
CVE-2025-2254 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 8.7 | 0% Низкий | 8 месяцев назад | |
CVE-2025-2246 An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API. | CVSS3: 5.8 | 0% Низкий | 6 месяцев назад | |
CVE-2025-2246 An issue has been discovered in GitLab CE/EE affecting all versions be ... | CVSS3: 5.8 | 0% Низкий | 6 месяцев назад | |
CVE-2025-2242 An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects. | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
CVE-2025-2242 An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects. | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
CVE-2025-2242 An improper access control vulnerability in GitLab CE/EE affecting all ... | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
CVE-2025-2045 Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data. | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
CVE-2025-2045 Improper authorization in GitLab EE affecting all versions from 17.7 p ... | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу