Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

debian логотип

CVE-2025-1299

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-12983

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-12983

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2025-12983

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2025-1278

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-1278

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-1278

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-12734

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-12734

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2025-12734

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2025-12716

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-12716

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-12704

22 дня назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2025-12704

22 дня назад

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2025-12697

22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

CVSS3: 2.2
EPSS: Низкий
nvd логотип

CVE-2025-12697

22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

CVSS3: 2.2
EPSS: Низкий
debian логотип

CVE-2025-12697

22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 2.2
EPSS: Низкий
nvd логотип

CVE-2025-12653

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-12653

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-1257

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2025-1299

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-12983

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.

CVSS3: 3.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-12983

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.

CVSS3: 3.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-12983

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-1278

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-1278

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-1278

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

CVSS3: 3.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

CVSS3: 3.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-12716

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.

CVSS3: 8.7
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-12716

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-12704

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions.

CVSS3: 3.5
0%
Низкий
22 дня назад
debian логотип
CVE-2025-12704

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 3.5
0%
Низкий
22 дня назад
ubuntu логотип
CVE-2025-12697

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

CVSS3: 2.2
0%
Низкий
22 дня назад
nvd логотип
CVE-2025-12697

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

CVSS3: 2.2
0%
Низкий
22 дня назад
debian логотип
CVE-2025-12697

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 2.2
0%
Низкий
22 дня назад
nvd логотип
CVE-2025-12653

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

CVSS3: 6.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-12653

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-1257

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

CVSS3: 6.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу