Количество 5 544
Количество 5 544
CVE-2024-8647
An issue was discovered in GitLab affecting all versions starting 15.2 ...
CVE-2024-8641
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.
CVE-2024-8641
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.
CVE-2024-8641
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2024-8640
An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.
CVE-2024-8640
An issue has been discovered in GitLab EE affecting all versions start ...
CVE-2024-8635
A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL
CVE-2024-8635
A server-side request forgery issue has been discovered in GitLab EE a ...
CVE-2024-8631
A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.
CVE-2024-8631
A privilege escalation issue has been discovered in GitLab EE affectin ...
CVE-2024-8402
An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
CVE-2024-8402
An issue was discovered in GitLab EE affecting all versions starting f ...
CVE-2024-8312
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
CVE-2024-8312
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
CVE-2024-8312
An issue has been discovered in GitLab CE/EE affecting all versions fr ...
CVE-2024-8311
An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.
CVE-2024-8311
An issue was discovered with pipeline execution policies in GitLab EE ...
CVE-2024-8266
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.
CVE-2024-8266
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.
CVE-2024-8266
An issue was discovered in GitLab CE/EE affecting all versions startin ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-8647 An issue was discovered in GitLab affecting all versions starting 15.2 ... | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-8641 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim. | CVSS3: 6.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-8641 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim. | CVSS3: 6.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-8641 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 6.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-8640 An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server. | CVSS3: 8.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-8640 An issue has been discovered in GitLab EE affecting all versions start ... | CVSS3: 8.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-8635 A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL | CVSS3: 7.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-8635 A server-side request forgery issue has been discovered in GitLab EE a ... | CVSS3: 7.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-8631 A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-8631 A privilege escalation issue has been discovered in GitLab EE affectin ... | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-8402 An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code. | CVSS3: 3.7 | 0% Низкий | около 1 года назад | |
CVE-2024-8402 An issue was discovered in GitLab EE affecting all versions starting f ... | CVSS3: 3.7 | 0% Низкий | около 1 года назад | |
CVE-2024-8312 An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS. | CVSS3: 8.7 | 2% Низкий | больше 1 года назад | |
CVE-2024-8312 An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS. | CVSS3: 8.7 | 2% Низкий | больше 1 года назад | |
CVE-2024-8312 An issue has been discovered in GitLab CE/EE affecting all versions fr ... | CVSS3: 8.7 | 2% Низкий | больше 1 года назад | |
CVE-2024-8311 An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-8311 An issue was discovered with pipeline execution policies in GitLab EE ... | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-8266 An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances. | CVSS3: 4.4 | 0% Низкий | около 1 года назад | |
CVE-2024-8266 An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances. | CVSS3: 4.4 | 0% Низкий | около 1 года назад | |
CVE-2024-8266 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 4.4 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу