Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

debian логотип

CVE-2025-1478

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-1477

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-1477

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-1477

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-14595

7 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user with Planner role to view security category metadata and attributes in group security configuration due to improper access control

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-14595

7 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-14594

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-14594

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2025-14594

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2025-14592

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-14592

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-14592

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2025-14560

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2025-14560

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2025-14560

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2025-14513

3 дня назад

(GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-14513

21 день назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-14513

21 день назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-14511

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-14511

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2025-1478

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-1477

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-1477

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-1477

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-14595

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user with Planner role to view security category metadata and attributes in group security configuration due to improper access control

CVSS3: 4.3
0%
Низкий
7 дней назад
debian логотип
CVE-2025-14595

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 4.3
0%
Низкий
7 дней назад
ubuntu логотип
CVE-2025-14594

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

CVSS3: 3.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-14594

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

CVSS3: 3.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-14594

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2025-14592

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-14592

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-14592

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2025-14560

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.

CVSS3: 7.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-14560

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.

CVSS3: 7.3
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-14560

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.3
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2025-14513

(GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)

CVSS3: 7.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2025-14513

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.

CVSS3: 7.5
0%
Низкий
21 день назад
debian логотип
CVE-2025-14513

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
0%
Низкий
21 день назад
ubuntu логотип
CVE-2025-14511

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-14511

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу