Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2024-1347

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2024-1347

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-1347

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-1347

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-13054

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-13054

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-13054

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions before ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-13041

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2024-13041

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2024-13041

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.2
EPSS: Низкий
ubuntu логотип

CVE-2024-1299

около 2 лет назад

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-1299

около 2 лет назад

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-1299

около 2 лет назад

A privilege escalation vulnerability was discovered in GitLab affectin ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-12619

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.

CVSS3: 5.2
EPSS: Низкий
nvd логотип

CVE-2024-12619

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.

CVSS3: 5.2
EPSS: Низкий
debian логотип

CVE-2024-12619

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.2
EPSS: Низкий
ubuntu логотип

CVE-2024-12570

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2024-12570

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2024-12570

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2024-1250

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-1347

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-1347

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-1347

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-1347

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-13054

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

CVSS3: 6.5
2%
Низкий
около 1 года назад
nvd логотип
CVE-2024-13054

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

CVSS3: 6.5
2%
Низкий
около 1 года назад
debian логотип
CVE-2024-13054

An issue was discovered in GitLab CE/EE affecting all versions before ...

CVSS3: 6.5
2%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-13041

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.

CVSS3: 4.2
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-13041

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.

CVSS3: 4.2
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-13041

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.2
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-1299

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-1299

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-1299

A privilege escalation vulnerability was discovered in GitLab affectin ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-12619

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.

CVSS3: 5.2
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-12619

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.

CVSS3: 5.2
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-12619

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.2
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-12570

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-12570

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-12570

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.7
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-1250

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу