Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2024-5318

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4
EPSS: Низкий
ubuntu логотип

CVE-2024-5258

почти 2 года назад

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-5258

почти 2 года назад

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-5258

почти 2 года назад

An authorization vulnerability exists within GitLab from versions 16.1 ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2024-5257

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2024-5257

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2024-5257

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2024-5067

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-5067

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2024-5005

больше 1 года назад

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-5005

больше 1 года назад

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-5005

больше 1 года назад

An issue has been discovered discovered in GitLab EE/CE affecting all ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-4994

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2024-4994

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2024-4994

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2024-4901

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-4901

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2024-4901

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2024-4835

почти 2 года назад

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2024-4835

почти 2 года назад

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2024-5318

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-5258

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-5258

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-5258

An authorization vulnerability exists within GitLab from versions 16.1 ...

CVSS3: 4.4
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-5257

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5257

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5257

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.9
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5067

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5067

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-5005

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5005

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5005

An issue has been discovered discovered in GitLab EE/CE affecting all ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-4994

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-4994

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-4994

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.1
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2024-4901

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
5%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-4901

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

CVSS3: 8.7
5%
Низкий
почти 2 года назад
debian логотип
CVE-2024-4901

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.7
5%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-4835

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
7%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-4835

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVSS3: 8
7%
Низкий
почти 2 года назад

Уязвимостей на страницу