Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 556

Количество 4 556

github логотип

GHSA-xcv9-mgjj-4fmc

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xcc5-p2w6-cc26

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-xc57-g4hr-v2m6

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xc4q-wvjc-4v56

8 месяцев назад

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xc35-m6pj-p4jm

около 3 лет назад

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x995-5r6x-9xh3

около 3 лет назад

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-x995-4q6w-crwj

больше 2 лет назад

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-x974-724g-rvvr

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x8x7-j36c-mp3c

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-x8pf-46vx-rg97

11 месяцев назад

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-x8mp-jv75-5hrp

около 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

EPSS: Низкий
github логотип

GHSA-x8c3-w66m-mxxx

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

EPSS: Низкий
github логотип

GHSA-x84c-7gqw-8475

около 3 лет назад

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

EPSS: Низкий
github логотип

GHSA-x7xf-pq3v-j78r

около 3 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x7v8-7cpc-hv73

больше 1 года назад

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-x79q-qfgr-wrvw

около 3 лет назад

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

EPSS: Низкий
github логотип

GHSA-x74g-xc7p-4fx7

больше 1 года назад

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x6g7-8j99-h4fv

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-x654-52cq-hxj3

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-x645-349v-xwm6

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xcv9-mgjj-4fmc

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

CVSS3: 5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xcc5-p2w6-cc26

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xc57-g4hr-v2m6

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xc4q-wvjc-4v56

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

CVSS3: 9.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-xc35-m6pj-p4jm

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-x995-5r6x-9xh3

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x995-4q6w-crwj

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-x974-724g-rvvr

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-x8x7-j36c-mp3c

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

CVSS3: 3.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-x8pf-46vx-rg97

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

CVSS3: 7.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-x8mp-jv75-5hrp

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x8c3-w66m-mxxx

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x84c-7gqw-8475

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x7xf-pq3v-j78r

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-x7v8-7cpc-hv73

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS3: 9.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-x79q-qfgr-wrvw

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x74g-xc7p-4fx7

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-x6g7-8j99-h4fv

An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x654-52cq-hxj3

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
0%
Низкий
9 месяцев назад
github логотип
GHSA-x645-349v-xwm6

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
0%
Низкий
больше 1 года назад

Уязвимостей на страницу