Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

nvd логотип

CVE-2024-9596

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2024-9596

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2024-9512

10 месяцев назад

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-9512

10 месяцев назад

An issue has been discovered in GitLab EE affecting all versions prior ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-9387

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2024-9387

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2024-9387

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 11 ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2024-9367

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-9367

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-9367

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-9183

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2024-9183

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2024-9164

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2024-9164

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2024-9164

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 9.6
EPSS: Низкий
ubuntu логотип

CVE-2024-9163

10 месяцев назад

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2024-9163

10 месяцев назад

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2024-9163

10 месяцев назад

A business logic error in GitLab CE/EE affecting all versions starting ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2024-8977

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2024-8977

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-9596

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9596

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9512

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-9512

An issue has been discovered in GitLab EE affecting all versions prior ...

CVSS3: 5.3
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2024-9387

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9387

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9387

An issue was discovered in GitLab CE/EE affecting all versions from 11 ...

CVSS3: 6.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-9367

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9367

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9367

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9183

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.

CVSS3: 7.7
0%
Низкий
4 месяца назад
debian логотип
CVE-2024-9183

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.7
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2024-9164

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

CVSS3: 9.6
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9164

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

CVSS3: 9.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9164

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 9.6
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-9163

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

CVSS3: 3.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-9163

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

CVSS3: 3.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-9163

A business logic error in GitLab CE/EE affecting all versions starting ...

CVSS3: 3.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-8977

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8977

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.2
0%
Низкий
больше 1 года назад

Уязвимостей на страницу