Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 995

Количество 5 995

github логотип

GHSA-vhmr-xxmg-qhfg

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to a discussions endpoint.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vgrr-9p4p-xw4w

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vgp2-3hxm-6x85

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVSS3: 10
EPSS: Критический
github логотип

GHSA-vgcv-58jw-xrwf

больше 4 лет назад

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

EPSS: Низкий
github логотип

GHSA-vg95-5p98-2464

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vg8q-6f88-6vrh

больше 4 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vg85-gmcc-wrqw

почти 2 года назад

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-vfph-fvw4-j4xp

почти 2 года назад

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-vf84-rvwc-7mx6

больше 4 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-vcvx-j5vc-8jhr

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-vcvr-9mwv-w2g3

около 1 года назад

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-v9r7-fcc3-gg2v

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v9g5-36x8-7xmx

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-v95j-qhvj-8v9x

больше 4 лет назад

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

EPSS: Низкий
github логотип

GHSA-v93g-p6q6-9wwq

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry disabled due to incorrect authorization checks in the group packages feature.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v92j-h587-3vv3

почти 4 года назад

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v8g6-hvf8-9cwq

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v84c-53c6-xmmp

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v7wh-rwr5-886x

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v6xp-h7ww-6xqf

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vhmr-xxmg-qhfg

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to a discussions endpoint.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-vgrr-9p4p-xw4w

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-vgp2-3hxm-6x85

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVSS3: 10
100%
Критический
больше 4 лет назад
github логотип
GHSA-vgcv-58jw-xrwf

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vg95-5p98-2464

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-vg8q-6f88-6vrh

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-vg85-gmcc-wrqw

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

CVSS3: 2.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-vfph-fvw4-j4xp

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-vf84-rvwc-7mx6

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vcvx-j5vc-8jhr

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard.

CVSS3: 8.7
0%
Низкий
4 месяца назад
github логотип
GHSA-vcvr-9mwv-w2g3

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-v9r7-fcc3-gg2v

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-v9g5-36x8-7xmx

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-v95j-qhvj-8v9x

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-v93g-p6q6-9wwq

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry disabled due to incorrect authorization checks in the group packages feature.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-v92j-h587-3vv3

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-v8g6-hvf8-9cwq

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-v84c-53c6-xmmp

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-v7wh-rwr5-886x

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-v6xp-h7ww-6xqf

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
0%
Низкий
почти 2 года назад

Уязвимостей на страницу