Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

nvd логотип

CVE-2024-8116

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-8116

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-8114

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2024-8114

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2024-8114

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2024-8041

больше 1 года назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-8041

больше 1 года назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-8041

больше 1 года назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE af ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-7803

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-7803

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-7803

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-7610

больше 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-7610

больше 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-7610

больше 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-7586

10 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

CVSS3: 4.1
EPSS: Низкий
nvd логотип

CVE-2024-7586

10 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

CVSS3: 4.1
EPSS: Низкий
debian логотип

CVE-2024-7586

10 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.1
EPSS: Низкий
ubuntu логотип

CVE-2024-7554

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2024-7554

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2024-7554

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-8116

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8116

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8114

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8114

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8114

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.2
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-8041

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-8041

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8041

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE af ...

CVSS3: 6.5
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-7803

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-7803

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-7803

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2024-7610

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-7610

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-7610

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-7586

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

CVSS3: 4.1
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-7586

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

CVSS3: 4.1
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-7586

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.1
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2024-7554

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-7554

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-7554

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.9
0%
Низкий
больше 1 года назад

Уязвимостей на страницу