Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

debian логотип

CVE-2025-2937

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-2934

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-2934

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-2934

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-2867

около 1 года назад

An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2025-2853

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-2853

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-2853

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-2615

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-2615

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-2615

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-2614

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive server resources when processed.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-2614

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive server resources when processed.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-2614

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-2498

8 месяцев назад

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-2498

8 месяцев назад

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-2498

8 месяцев назад

An improper access control in Gitlab EE affecting all versions from 12 ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-2469

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-2469

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2025-2443

10 месяцев назад

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2025-2937

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-2934

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-2934

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-2934

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-2867

An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.

CVSS3: 4.4
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-2853

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-2853

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-2853

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.5
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-2615

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-2615

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-2615

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-2614

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive server resources when processed.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-2614

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive server resources when processed.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-2614

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-2498

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

CVSS3: 3.1
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-2498

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

CVSS3: 3.1
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-2498

An improper access control in Gitlab EE affecting all versions from 12 ...

CVSS3: 3.1
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-2469

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.

CVSS3: 3.7
0%
Низкий
12 месяцев назад
debian логотип
CVE-2025-2469

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.7
0%
Низкий
12 месяцев назад
ubuntu логотип
CVE-2025-2443

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
0%
Низкий
10 месяцев назад

Уязвимостей на страницу