Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2024-5528

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2024-5528

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2024-5528

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions prior t ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2024-5470

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2024-5470

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
EPSS: Низкий
debian логотип

CVE-2024-5470

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.8
EPSS: Низкий
ubuntu логотип

CVE-2024-5469

почти 2 года назад

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-5469

почти 2 года назад

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2024-5469

почти 2 года назад

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior t ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2024-5435

больше 1 года назад

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

CVSS3: 4.5
EPSS: Низкий
nvd логотип

CVE-2024-5435

больше 1 года назад

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

CVSS3: 4.5
EPSS: Низкий
debian логотип

CVE-2024-5435

больше 1 года назад

An issue has been discovered discovered in GitLab EE/CE affecting all ...

CVSS3: 4.5
EPSS: Низкий
ubuntu логотип

CVE-2024-5430

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2024-5430

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-5430

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2024-5423

больше 1 года назад

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-5423

больше 1 года назад

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-5423

больше 1 года назад

Multiple Denial of Service (DoS) conditions has been discovered in Git ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-5318

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2024-5318

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

CVSS3: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-5528

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

CVSS3: 3.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-5528

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

CVSS3: 3.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-5528

An issue was discovered in GitLab CE/EE affecting all versions prior t ...

CVSS3: 3.5
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-5470

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5470

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

CVSS3: 3.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5470

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.8
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-5469

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-5469

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-5469

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior t ...

CVSS3: 3.1
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-5435

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

CVSS3: 4.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5435

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

CVSS3: 4.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5435

An issue has been discovered discovered in GitLab EE/CE affecting all ...

CVSS3: 4.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-5430

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-5430

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

CVSS3: 6.8
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-5430

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.8
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-5423

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5423

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5423

Multiple Denial of Service (DoS) conditions has been discovered in Git ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-5318

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

CVSS3: 4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-5318

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

CVSS3: 4
0%
Низкий
почти 2 года назад

Уязвимостей на страницу