Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2024-4024

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2024-4011

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-4011

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2024-4011

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2024-4006

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-4006

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-4006

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-3976

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-3976

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-3976

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-3959

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-3959

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-3959

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-3958

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-3958

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-3958

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-3303

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2024-3303

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2024-3303

около 1 года назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2024-3127

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2024-4024

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.3
3%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-4011

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

CVSS3: 3.1
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-4011

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

CVSS3: 3.1
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-4011

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.1
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-4006

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

CVSS3: 4.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-4006

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

CVSS3: 4.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-4006

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-3976

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-3976

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.

CVSS3: 6.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-3976

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-3959

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-3959

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-3959

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 6.5
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-3958

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-3958

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-3958

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-3303

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

CVSS3: 6.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-3303

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

CVSS3: 6.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-3303

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 6.4
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-3127

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу