Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 995

Количество 5 995

github логотип

GHSA-v6wj-hx5h-fhwp

больше 4 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v68j-qxmr-9486

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v64g-f7qf-63xm

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v648-cf9r-9m29

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v575-96v9-gxhw

больше 1 года назад

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-v52q-48v6-rmj4

12 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v4qw-4358-7wh4

почти 5 лет назад

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

EPSS: Низкий
github логотип

GHSA-v4cx-jmp6-mgf4

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-v488-9cvj-5mx7

больше 1 года назад

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v3p6-8992-mc58

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-v3j6-jv37-286j

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-v3gx-42r7-j2h7

4 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper validation.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-v2jw-9cf3-v6vg

больше 4 лет назад

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.

EPSS: Низкий
github логотип

GHSA-v2gw-42rh-8v5g

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-v254-7f59-gpqj

около 4 лет назад

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-v253-xqc5-h554

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

EPSS: Низкий
github логотип

GHSA-rxh8-jh3g-ccqq

больше 4 лет назад

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-rxf6-f2p5-q27m

больше 4 лет назад

An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.

EPSS: Низкий
github логотип

GHSA-rwwp-3rv3-j6q6

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rww2-m274-8f9v

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-v6wj-hx5h-fhwp

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-v68j-qxmr-9486

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-v64g-f7qf-63xm

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-v648-cf9r-9m29

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-v575-96v9-gxhw

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS3: 8.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-v52q-48v6-rmj4

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-v4qw-4358-7wh4

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

1%
Низкий
почти 5 лет назад
github логотип
GHSA-v4cx-jmp6-mgf4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-v488-9cvj-5mx7

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-v3p6-8992-mc58

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).

CVSS3: 3.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-v3j6-jv37-286j

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.

CVSS3: 6.5
33%
Средний
больше 2 лет назад
github логотип
GHSA-v3gx-42r7-j2h7

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper validation.

CVSS3: 3.5
0%
Низкий
4 месяца назад
github логотип
GHSA-v2jw-9cf3-v6vg

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-v2gw-42rh-8v5g

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.

CVSS3: 5
0%
Низкий
около 3 лет назад
github логотип
GHSA-v254-7f59-gpqj

A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-v253-xqc5-h554

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-rxh8-jh3g-ccqq

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

CVSS3: 8.8
10%
Средний
больше 4 лет назад
github логотип
GHSA-rxf6-f2p5-q27m

An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-rwwp-3rv3-j6q6

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-rww2-m274-8f9v

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

CVSS3: 8.7
0%
Низкий
больше 1 года назад

Уязвимостей на страницу