Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

ubuntu логотип

CVE-2024-8974

больше 1 года назад

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2024-8974

больше 1 года назад

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2024-8974

больше 1 года назад

Information disclosure in Gitlab EE/CE affecting all versions from 15. ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2024-8973

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-8973

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-8973

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-8970

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2024-8970

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2024-8970

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2024-8754

больше 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2024-8754

больше 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2024-8754

больше 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions fr ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2024-8650

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-8650

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-8650

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions from 15 ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-8648

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-8648

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-8648

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2024-8647

больше 1 года назад

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-8647

больше 1 года назад

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-8974

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

CVSS3: 2.6
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8974

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

CVSS3: 2.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8974

Information disclosure in Gitlab EE/CE affecting all versions from 15. ...

CVSS3: 2.6
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8973

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2024-8973

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2024-8973

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2024-8970

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8970

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8970

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.2
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8754

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8754

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8754

An issue has been discovered in GitLab EE/CE affecting all versions fr ...

CVSS3: 6.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8650

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8650

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8650

An issue was discovered in GitLab CE/EE affecting all versions from 15 ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8648

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

CVSS3: 6.1
3%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8648

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

CVSS3: 6.1
3%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8648

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.1
3%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8647

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8647

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу