Количество 5 545
Количество 5 545
CVE-2024-7404
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.
CVE-2024-7404
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-7296
An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.
CVE-2024-7296
An issue was discovered in GitLab EE affecting all versions from 16.5 ...
CVE-2024-7110
An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection.
CVE-2024-7110
An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection.
CVE-2024-7110
An issue was discovered in GitLab EE affecting all versions starting 1 ...
CVE-2024-7102
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.
CVE-2024-7102
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.
CVE-2024-7102
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-7091
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.
CVE-2024-7091
An issue was discovered in GitLab CE/EE affecting all versions startin ...
CVE-2024-7060
An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.
CVE-2024-7060
An information disclosure vulnerability in GitLab CE/EE in project/gro ...
CVE-2024-7057
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.
CVE-2024-7057
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.
CVE-2024-7057
An information disclosure vulnerability in GitLab CE/EE affecting all ...
CVE-2024-7047
A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.
CVE-2024-7047
A cross site scripting vulnerability exists in GitLab CE/EE affecting ...
CVE-2024-6826
An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-7404 An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow. | CVSS3: 6.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-7404 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 6.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-7296 An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users. | CVSS3: 2.7 | 0% Низкий | около 1 года назад | |
CVE-2024-7296 An issue was discovered in GitLab EE affecting all versions from 16.5 ... | CVSS3: 2.7 | 0% Низкий | около 1 года назад | |
CVE-2024-7110 An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection. | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-7110 An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection. | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-7110 An issue was discovered in GitLab EE affecting all versions starting 1 ... | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-7102 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances. | CVSS3: 9.6 | 0% Низкий | около 1 года назад | |
CVE-2024-7102 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances. | CVSS3: 9.6 | 0% Низкий | около 1 года назад | |
CVE-2024-7102 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 9.6 | 0% Низкий | около 1 года назад | |
CVE-2024-7091 An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user. | CVSS3: 4.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-7091 An issue was discovered in GitLab CE/EE affecting all versions startin ... | CVSS3: 4.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-7060 An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export. | CVSS3: 2.6 | 0% Низкий | больше 1 года назад | |
CVE-2024-7060 An information disclosure vulnerability in GitLab CE/EE in project/gro ... | CVSS3: 2.6 | 0% Низкий | больше 1 года назад | |
CVE-2024-7057 An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-7057 An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-7057 An information disclosure vulnerability in GitLab CE/EE affecting all ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-7047 A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user. | CVSS3: 7.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-7047 A cross site scripting vulnerability exists in GitLab CE/EE affecting ... | CVSS3: 7.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-6826 An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу