Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 237

Количество 5 237

github логотип

GHSA-xg8m-gfp3-4fv6

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

EPSS: Низкий
github логотип

GHSA-xg8m-4qxg-vm4m

больше 2 лет назад

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xg29-cfqc-hqpr

больше 3 лет назад

An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xfxc-c47w-9432

больше 3 лет назад

An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xcw3-xf4g-cwjj

около 3 лет назад

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xcv9-mgjj-4fmc

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xcc5-p2w6-cc26

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.

EPSS: Низкий
github логотип

GHSA-xc57-g4hr-v2m6

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xc4q-wvjc-4v56

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xc35-m6pj-p4jm

больше 3 лет назад

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x995-5r6x-9xh3

больше 3 лет назад

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-x995-4q6w-crwj

около 3 лет назад

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-x974-724g-rvvr

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x8x7-j36c-mp3c

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-x8pr-qx2m-cr7g

28 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-x8pf-46vx-rg97

больше 1 года назад

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-x8mp-jv75-5hrp

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

EPSS: Низкий
github логотип

GHSA-x8c3-w66m-mxxx

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

EPSS: Низкий
github логотип

GHSA-x84c-7gqw-8475

больше 3 лет назад

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

EPSS: Низкий
github логотип

GHSA-x7xf-pq3v-j78r

больше 3 лет назад

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg8m-gfp3-4fv6

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xg8m-4qxg-vm4m

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 3.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xg29-cfqc-hqpr

An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xfxc-c47w-9432

An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xcw3-xf4g-cwjj

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 7.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xcv9-mgjj-4fmc

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

CVSS3: 5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xcc5-p2w6-cc26

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xc57-g4hr-v2m6

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xc4q-wvjc-4v56

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

CVSS3: 9.6
0%
Низкий
около 1 года назад
github логотип
GHSA-xc35-m6pj-p4jm

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-x995-5r6x-9xh3

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x995-4q6w-crwj

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 8
0%
Низкий
около 3 лет назад
github логотип
GHSA-x974-724g-rvvr

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-x8x7-j36c-mp3c

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-x8pr-qx2m-cr7g

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5
0%
Низкий
28 дней назад
github логотип
GHSA-x8pf-46vx-rg97

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-x8mp-jv75-5hrp

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x8c3-w66m-mxxx

An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x84c-7gqw-8475

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x7xf-pq3v-j78r

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу