Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2024-3127

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-3127

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-3115

почти 2 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-3115

почти 2 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-3115

почти 2 года назад

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-3114

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-3114

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-3114

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-3092

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-3092

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2024-3092

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2024-3035

больше 1 года назад

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2024-3035

больше 1 года назад

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-3035

больше 1 года назад

A permission check vulnerability in GitLab CE/EE affecting all version ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2024-2880

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2024-2880

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2024-2880

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2024-2878

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-2878

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-2878

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-3127

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-3127

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-3115

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-3115

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-3115

An issue was discovered in GitLab EE affecting all versions starting f ...

CVSS3: 4.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-3114

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-3114

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-3114

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-3092

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-3092

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-3092

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-3035

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-3035

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-3035

A permission check vulnerability in GitLab CE/EE affecting all version ...

CVSS3: 6.8
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-2880

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

CVSS3: 2.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-2880

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

CVSS3: 2.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2880

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 2.7
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-2878

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.

CVSS3: 7.5
5%
Низкий
около 1 года назад
nvd логотип
CVE-2024-2878

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.

CVSS3: 7.5
5%
Низкий
около 1 года назад
debian логотип
CVE-2024-2878

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
5%
Низкий
около 1 года назад

Уязвимостей на страницу