Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

nvd логотип

CVE-2025-0765

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-0765

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-0679

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-0679

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-0679

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-0673

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-0673

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-0673

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-0652

около 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-0652

около 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-0652

около 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-0639

11 месяцев назад

An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-0639

11 месяцев назад

An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-0639

11 месяцев назад

An issue has been discovered affecting service availability via issue ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-0605

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2025-0605

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
EPSS: Низкий
debian логотип

CVE-2025-0605

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2025-0555

около 1 года назад

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2025-0555

около 1 года назад

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2025-0549

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-0765

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-0765

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.3
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-0679

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-0679

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-0679

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.3
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-0673

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-0673

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-0673

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 7.5
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-0652

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-0652

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-0652

An issue has been discovered in GitLab EE/CE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-0639

An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-0639

An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-0639

An issue has been discovered affecting service availability via issue ...

CVSS3: 6.5
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-0605

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-0605

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

CVSS3: 4.6
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-0605

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.6
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-0555

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-0555

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all ...

CVSS3: 7.7
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-0549

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction.

CVSS3: 6.8
0%
Низкий
11 месяцев назад

Уязвимостей на страницу