Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2024-2454

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-2434

почти 2 года назад

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
EPSS: Средний
redhat логотип

CVE-2024-2434

почти 2 года назад

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
EPSS: Средний
nvd логотип

CVE-2024-2434

почти 2 года назад

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
EPSS: Средний
debian логотип

CVE-2024-2434

почти 2 года назад

An issue has been discovered in GitLab affecting all versions of GitLa ...

CVSS3: 8.5
EPSS: Средний
ubuntu логотип

CVE-2024-2279

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-2279

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2024-2279

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2024-2191

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-2191

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-2191

почти 2 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-2177

больше 1 года назад

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2024-2177

больше 1 года назад

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-2177

больше 1 года назад

A Cross Window Forgery vulnerability exists within GitLab CE/EE affect ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2024-1963

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-1963

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-1963

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-1947

почти 2 года назад

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-1947

почти 2 года назад

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-1947

почти 2 года назад

A denial of service (DoS) condition was discovered in GitLab CE/EE aff ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2024-2454

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
2%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-2434

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
11%
Средний
почти 2 года назад
redhat логотип
CVE-2024-2434

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
11%
Средний
почти 2 года назад
nvd логотип
CVE-2024-2434

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

CVSS3: 8.5
11%
Средний
почти 2 года назад
debian логотип
CVE-2024-2434

An issue has been discovered in GitLab affecting all versions of GitLa ...

CVSS3: 8.5
11%
Средний
почти 2 года назад
ubuntu логотип
CVE-2024-2279

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-2279

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-2279

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-2191

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-2191

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-2191

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 5.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-2177

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-2177

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2177

A Cross Window Forgery vulnerability exists within GitLab CE/EE affect ...

CVSS3: 6.8
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-1963

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-1963

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-1963

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-1947

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-1947

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-1947

A denial of service (DoS) condition was discovered in GitLab CE/EE aff ...

CVSS3: 4.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу