Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 904

Количество 4 904

github логотип

GHSA-r4qm-gf89-653c

около 3 лет назад

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

EPSS: Низкий
github логотип

GHSA-r45q-p6m3-6gmv

больше 3 лет назад

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

EPSS: Низкий
github логотип

GHSA-r42x-m65m-82x8

около 3 лет назад

GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.

EPSS: Низкий
github логотип

GHSA-r3mm-qxv5-x23h

9 месяцев назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-r3m4-8xwf-9fpp

3 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-r375-6xr6-qqjq

4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-r365-c863-wwvq

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-qxr4-8jqx-8c2w

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-qxgw-h378-xhrw

около 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.

EPSS: Низкий
github логотип

GHSA-qx5w-mmcc-hg72

около 3 лет назад

Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions

EPSS: Низкий
github логотип

GHSA-qx55-2cp2-7ppq

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-qwxw-v6wx-qh2q

больше 2 лет назад

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-qw5x-x275-9wwh

почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qvhh-qrj8-5g7c

12 месяцев назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qvh8-3fcf-c54f

около 3 лет назад

Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

EPSS: Низкий
github логотип

GHSA-qvg5-w5f4-rcwh

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-qv5m-w8c2-586r

около 3 лет назад

GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-qrrr-vqv8-9hcw

почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qrp8-hgrf-wv83

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-qrcv-45vg-jfwm

около 3 лет назад

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-r4qm-gf89-653c

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

0%
Низкий
около 3 лет назад
github логотип
GHSA-r45q-p6m3-6gmv

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

0%
Низкий
больше 3 лет назад
github логотип
GHSA-r42x-m65m-82x8

GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.

0%
Низкий
около 3 лет назад
github логотип
GHSA-r3mm-qxv5-x23h

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file.

CVSS3: 6.5
1%
Низкий
9 месяцев назад
github логотип
GHSA-r3m4-8xwf-9fpp

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-r375-6xr6-qqjq

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-r365-c863-wwvq

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-qxr4-8jqx-8c2w

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
53%
Средний
почти 3 года назад
github логотип
GHSA-qxgw-h378-xhrw

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.

0%
Низкий
около 3 лет назад
github логотип
GHSA-qx5w-mmcc-hg72

Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions

0%
Низкий
около 3 лет назад
github логотип
GHSA-qx55-2cp2-7ppq

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

CVSS3: 3.1
4%
Низкий
около 2 лет назад
github логотип
GHSA-qwxw-v6wx-qh2q

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.

CVSS3: 5.3
2%
Низкий
больше 2 лет назад
github логотип
GHSA-qw5x-x275-9wwh

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-qvhh-qrj8-5g7c

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS3: 6.5
1%
Низкий
12 месяцев назад
github логотип
GHSA-qvh8-3fcf-c54f

Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

0%
Низкий
около 3 лет назад
github логотип
GHSA-qvg5-w5f4-rcwh

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-qv5m-w8c2-586r

GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.

0%
Низкий
около 3 лет назад
github логотип
GHSA-qrrr-vqv8-9hcw

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-qrp8-hgrf-wv83

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.

CVSS3: 8.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-qrcv-45vg-jfwm

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу