Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2024-4283

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2024-4283

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2024-4278

больше 1 года назад

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-4278

больше 1 года назад

An information disclosure issue has been discovered in GitLab EE affec ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2024-4210

больше 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-4210

больше 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-4210

больше 1 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-4207

больше 1 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-4207

больше 1 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-4207

больше 1 года назад

A cross-site scripting issue has been discovered in GitLab affecting a ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2024-4201

почти 2 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-4201

почти 2 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-4201

почти 2 года назад

A cross-site scripting issue has been discovered in GitLab affecting a ...

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-4099

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2024-4099

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2024-4025

10 месяцев назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-4025

10 месяцев назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-4025

10 месяцев назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-4024

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2024-4024

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-4283

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-4283

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-4278

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-4278

An information disclosure issue has been discovered in GitLab EE affec ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-4210

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-4210

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-4210

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-4207

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-4207

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-4207

A cross-site scripting issue has been discovered in GitLab affecting a ...

CVSS3: 4.4
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-4201

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-4201

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVSS3: 4.4
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-4201

A cross-site scripting issue has been discovered in GitLab affecting a ...

CVSS3: 4.4
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-4099

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection.

CVSS3: 3.1
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-4099

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-4025

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-4025

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-4025

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 6.5
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2024-4024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.

CVSS3: 7.3
3%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-4024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.

CVSS3: 7.3
3%
Низкий
почти 2 года назад

Уязвимостей на страницу