Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

debian логотип

CVE-2024-8647

больше 1 года назад

An issue was discovered in GitLab affecting all versions starting 15.2 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2024-8641

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2024-8641

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2024-8641

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2024-8640

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

CVSS3: 8.5
EPSS: Низкий
debian логотип

CVE-2024-8640

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2024-8635

больше 1 года назад

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2024-8635

больше 1 года назад

A server-side request forgery issue has been discovered in GitLab EE a ...

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2024-8631

больше 1 года назад

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-8631

больше 1 года назад

A privilege escalation issue has been discovered in GitLab EE affectin ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2024-8402

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2024-8402

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2024-8312

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-8312

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2024-8312

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-8311

больше 1 года назад

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-8311

больше 1 года назад

An issue was discovered with pipeline execution policies in GitLab EE ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-8266

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-8266

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-8266

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2024-8647

An issue was discovered in GitLab affecting all versions starting 15.2 ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8641

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8641

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8641

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8640

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8640

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8635

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

CVSS3: 7.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8635

A server-side request forgery issue has been discovered in GitLab EE a ...

CVSS3: 7.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8631

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8631

A privilege escalation issue has been discovered in GitLab EE affectin ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8402

An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.

CVSS3: 3.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-8402

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 3.7
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-8312

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.

CVSS3: 8.7
2%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8312

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.

CVSS3: 8.7
2%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8312

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
2%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8311

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8311

An issue was discovered with pipeline execution policies in GitLab EE ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8266

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVSS3: 4.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-8266

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVSS3: 4.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-8266

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу