Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 995

Количество 5 995

github логотип

GHSA-rm4p-54wj-px7w

почти 4 года назад

It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rjcp-5fmg-8753

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rhx5-h5p6-9g65

больше 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-rhvj-gv4v-wvcv

больше 4 лет назад

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rh9w-q6r6-5g3m

больше 4 лет назад

A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.

EPSS: Низкий
github логотип

GHSA-rh5v-9jwc-7736

9 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rgx6-gx96-7frc

около 2 лет назад

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-rg23-p49x-87gc

больше 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.

EPSS: Низкий
github логотип

GHSA-rfm6-5393-x9wf

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rfc5-457g-gpqm

больше 4 лет назад

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-rf7g-f56c-v6w4

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting incorrect authorization validation in API endpoints.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rcvw-fc36-wjhj

11 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-r9m9-87p7-xj9f

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-r998-qhmx-fp4x

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

EPSS: Низкий
github логотип

GHSA-r8rw-g922-j95j

больше 4 лет назад

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-r8qj-g779-h5pv

больше 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-r8m7-3v38-qjrm

29 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-r8f4-mx7h-29jp

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-r86w-x85m-w6rj

больше 4 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-r77r-m2hf-8495

больше 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rm4p-54wj-px7w

It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-rjcp-5fmg-8753

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-rhx5-h5p6-9g65

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS3: 7.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-rhvj-gv4v-wvcv

An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-rh9w-q6r6-5g3m

A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-rh5v-9jwc-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.

CVSS3: 6.5
1%
Низкий
9 месяцев назад
github логотип
GHSA-rgx6-gx96-7frc

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

CVSS3: 6.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-rg23-p49x-87gc

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-rfm6-5393-x9wf

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-rfc5-457g-gpqm

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 7.6
1%
Низкий
больше 4 лет назад
github логотип
GHSA-rf7g-f56c-v6w4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting incorrect authorization validation in API endpoints.

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-rcvw-fc36-wjhj

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-r9m9-87p7-xj9f

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-r998-qhmx-fp4x

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-r8rw-g922-j95j

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-r8qj-g779-h5pv

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-r8m7-3v38-qjrm

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.

CVSS3: 3.5
0%
Низкий
29 дней назад
github логотип
GHSA-r8f4-mx7h-29jp

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

CVSS3: 6.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-r86w-x85m-w6rj

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-r77r-m2hf-8495

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу