Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 237

Количество 5 237

github логотип

GHSA-rw3m-264q-5gp2

больше 3 лет назад

Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rvxr-qvvc-m3g5

больше 3 лет назад

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

EPSS: Низкий
github логотип

GHSA-rvj3-54w6-vrw6

больше 1 года назад

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-rvcw-fpwr-r263

почти 4 года назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

EPSS: Низкий
github логотип

GHSA-rrjx-38j3-wx7p

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rqgw-47f7-cww6

больше 3 лет назад

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where it was possible for an unauthorised user to execute arbitrary code on the server using the project import feature.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-rq9r-r987-7r36

больше 3 лет назад

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rq6q-w27x-f9x2

4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-rpq3-7r39-wr67

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.0 and through 12.0.2. Users with access to issues, but not the repository were able to view the number of related merge requests on an issue. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-rppq-5vq8-crrp

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-rp5v-chq5-pw9q

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rmhm-cwgp-268p

около 1 года назад

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rm66-gh27-q674

больше 3 лет назад

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

EPSS: Низкий
github логотип

GHSA-rm4r-vwvw-vj67

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rm4p-54wj-px7w

около 3 лет назад

It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rjcp-5fmg-8753

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rhx5-h5p6-9g65

почти 2 года назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-rhvj-gv4v-wvcv

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rh9w-q6r6-5g3m

больше 3 лет назад

A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.

EPSS: Низкий
github логотип

GHSA-rgx6-gx96-7frc

больше 1 года назад

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rw3m-264q-5gp2

Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-rvxr-qvvc-m3g5

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-rvj3-54w6-vrw6

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-rvcw-fpwr-r263

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

0%
Низкий
почти 4 года назад
github логотип
GHSA-rrjx-38j3-wx7p

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-rqgw-47f7-cww6

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where it was possible for an unauthorised user to execute arbitrary code on the server using the project import feature.

CVSS3: 9.8
93%
Критический
больше 3 лет назад
github логотип
GHSA-rq9r-r987-7r36

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-rq6q-w27x-f9x2

An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-rpq3-7r39-wr67

An issue was discovered in GitLab Community and Enterprise Edition 9.0 and through 12.0.2. Users with access to issues, but not the repository were able to view the number of related merge requests on an issue. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-rppq-5vq8-crrp

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.

CVSS3: 6.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-rp5v-chq5-pw9q

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-rmhm-cwgp-268p

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch.

CVSS3: 4.3
1%
Низкий
около 1 года назад
github логотип
GHSA-rm66-gh27-q674

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-rm4r-vwvw-vj67

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-rm4p-54wj-px7w

It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-rjcp-5fmg-8753

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-rhx5-h5p6-9g65

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS3: 7.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-rhvj-gv4v-wvcv

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-rh9w-q6r6-5g3m

A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-rgx6-gx96-7frc

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

CVSS3: 6.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу