Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2025-2443

8 месяцев назад

An issue has been discovered in GitLab EE that allows for cross-site-s ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-24397

около 1 года назад

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-2408

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-2408

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-2408

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-2256

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-2256

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-2255

11 месяцев назад

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-2255

11 месяцев назад

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-2255

11 месяцев назад

An issue has been discovered in Gitlab EE/CE for AppSec affecting all ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-2254

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-2254

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-2254

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-2246

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2025-2246

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2025-2242

11 месяцев назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-2242

11 месяцев назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-2242

11 месяцев назад

An improper access control vulnerability in GitLab CE/EE affecting all ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-2045

11 месяцев назад

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-2045

11 месяцев назад

Improper authorization in GitLab EE affecting all versions from 17.7 p ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2025-2443

An issue has been discovered in GitLab EE that allows for cross-site-s ...

CVSS3: 8.7
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-24397

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.

CVSS3: 4.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-2408

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-2408

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-2408

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-2256

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-2256

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-2255

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-2255

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

CVSS3: 8.7
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-2255

An issue has been discovered in Gitlab EE/CE for AppSec affecting all ...

CVSS3: 8.7
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-2254

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-2254

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-2254

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-2246

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5.8
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-2246

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.8
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-2242

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-2242

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-2242

An improper access control vulnerability in GitLab CE/EE affecting all ...

CVSS3: 7.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-2045

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-2045

Improper authorization in GitLab EE affecting all versions from 17.7 p ...

CVSS3: 4.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу