Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

nvd логотип

CVE-2025-13772

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2025-13772

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2025-13761

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2025-13761

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2025-13761

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2025-13690

22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certain conditions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-13690

22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certain conditions.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-13690

22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-13611

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

CVSS3: 2
EPSS: Низкий
debian логотип

CVE-2025-13611

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 2
EPSS: Низкий
ubuntu логотип

CVE-2025-13436

8 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-13436

8 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-13436

8 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-13335

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-13335

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-13335

2 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-13078

8 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhook configuration inputs.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-13078

8 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-1299

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorized user to read deployment job logs by sending a crafted request.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-1299

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorized user to read deployment job logs by sending a crafted request.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-13772

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.

CVSS3: 7.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-13772

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 7.1
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-13761

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-13761

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-13761

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-13690

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certain conditions.

CVSS3: 6.5
0%
Низкий
22 дня назад
nvd логотип
CVE-2025-13690

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certain conditions.

CVSS3: 6.5
0%
Низкий
22 дня назад
debian логотип
CVE-2025-13690

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
0%
Низкий
22 дня назад
nvd логотип
CVE-2025-13611

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

CVSS3: 2
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-13611

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 2
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-13436

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.

CVSS3: 6.5
0%
Низкий
8 дней назад
nvd логотип
CVE-2025-13436

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.

CVSS3: 6.5
0%
Низкий
8 дней назад
debian логотип
CVE-2025-13436

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2025-13335

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-13335

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

CVSS3: 6.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-13335

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-13078

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhook configuration inputs.

CVSS3: 6.5
0%
Низкий
8 дней назад
debian логотип
CVE-2025-13078

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
0%
Низкий
8 дней назад
ubuntu логотип
CVE-2025-1299

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorized user to read deployment job logs by sending a crafted request.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-1299

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorized user to read deployment job logs by sending a crafted request.

CVSS3: 4.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу