Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2024-6389

больше 1 года назад

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-6389

больше 1 года назад

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-6389

больше 1 года назад

An issue was discovered in GitLab-CE/EE affecting all versions startin ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-6385

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2024-6385

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2024-6385

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2024-6356

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-6356

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2024-6329

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2024-6329

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2024-6329

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2024-6324

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-6324

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-6324

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-6323

почти 2 года назад

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-6323

почти 2 года назад

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-6323

почти 2 года назад

Improper authorization in global search in GitLab EE affecting all ver ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-5655

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2024-5655

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2024-5655

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-6389

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6389

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-6389

An issue was discovered in GitLab-CE/EE affecting all versions startin ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-6385

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6385

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-6385

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.6
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6356

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.

CVSS3: 4.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-6356

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.4
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-6329

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6329

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-6329

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 5.7
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-6324

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.

CVSS3: 4.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-6324

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.

CVSS3: 4.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-6324

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-6323

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-6323

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-6323

Improper authorization in global search in GitLab EE affecting all ver ...

CVSS3: 7.5
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-5655

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-5655

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

CVSS3: 9.6
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-5655

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 9.6
1%
Низкий
почти 2 года назад

Уязвимостей на страницу