Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-v9r7-fcc3-gg2v

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v9g5-36x8-7xmx

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-v95j-qhvj-8v9x

почти 4 года назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

EPSS: Низкий
github логотип

GHSA-v92j-h587-3vv3

больше 3 лет назад

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v8g6-hvf8-9cwq

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v84c-53c6-xmmp

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v7wh-rwr5-886x

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v6xp-h7ww-6xqf

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-v6wj-hx5h-fhwp

почти 4 года назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v68j-qxmr-9486

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v64g-f7qf-63xm

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v648-cf9r-9m29

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v575-96v9-gxhw

около 1 года назад

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-v52q-48v6-rmj4

6 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v4qw-4358-7wh4

больше 4 лет назад

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

EPSS: Низкий
github логотип

GHSA-v488-9cvj-5mx7

около 1 года назад

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v3p6-8992-mc58

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-v3j6-jv37-286j

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v2jw-9cf3-v6vg

почти 4 года назад

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.

EPSS: Низкий
github логотип

GHSA-v2gw-42rh-8v5g

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-v9r7-fcc3-gg2v

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-v9g5-36x8-7xmx

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-v95j-qhvj-8v9x

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

0%
Низкий
почти 4 года назад
github логотип
GHSA-v92j-h587-3vv3

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-v8g6-hvf8-9cwq

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-v84c-53c6-xmmp

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-v7wh-rwr5-886x

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-v6xp-h7ww-6xqf

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-v6wj-hx5h-fhwp

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-v68j-qxmr-9486

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 4.3
2%
Низкий
около 3 лет назад
github логотип
GHSA-v64g-f7qf-63xm

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-v648-cf9r-9m29

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-v575-96v9-gxhw

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS3: 8.7
0%
Низкий
около 1 года назад
github логотип
GHSA-v52q-48v6-rmj4

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-v4qw-4358-7wh4

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

0%
Низкий
больше 4 лет назад
github логотип
GHSA-v488-9cvj-5mx7

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-v3p6-8992-mc58

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).

CVSS3: 3.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-v3j6-jv37-286j

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-v2jw-9cf3-v6vg

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.

0%
Низкий
почти 4 года назад
github логотип
GHSA-v2gw-42rh-8v5g

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.

CVSS3: 5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу