Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

ubuntu логотип

CVE-2025-12073

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-12073

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-12073

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-12029

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2025-12029

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2025-11990

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-11990

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-11990

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2025-1198

около 1 года назад

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2025-1198

около 1 года назад

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2025-1198

около 1 года назад

An issue discovered in GitLab CE/EE affecting all versions from 16.11 ...

CVSS3: 4.2
EPSS: Низкий
ubuntu логотип

CVE-2025-11989

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-11989

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-11989

5 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2025-11984

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2025-11984

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2025-11984

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2025-11974

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-11974

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-11974

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-12073

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-12073

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-12073

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-12029

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-12029

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-11990

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

CVSS3: 3.1
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-11990

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

CVSS3: 3.1
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-11990

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 3.1
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-1198

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

CVSS3: 4.2
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-1198

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

CVSS3: 4.2
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-1198

An issue discovered in GitLab CE/EE affecting all versions from 16.11 ...

CVSS3: 4.2
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-11989

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

CVSS3: 3.7
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-11989

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.

CVSS3: 3.7
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-11989

GitLab has remediated an issue in GitLab EE affecting all versions fro ...

CVSS3: 3.7
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-11984

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

CVSS3: 6.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11984

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

CVSS3: 6.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11984

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-11974

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-11974

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-11974

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу