Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2024-1250

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-1250

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-12431

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-12431

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-12431

около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-12380

около 1 года назад

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-12380

около 1 года назад

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-12380

около 1 года назад

An issue was discovered in GitLab EE/CE affecting all versions startin ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2024-12379

около 1 года назад

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-12379

около 1 года назад

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-12379

около 1 года назад

A denial of service vulnerability in GitLab CE/EE affecting all versio ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-12303

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2024-12303

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2024-12303

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2024-12292

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2024-12292

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2024-12292

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4
EPSS: Низкий
ubuntu логотип

CVE-2024-12244

11 месяцев назад

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-12244

11 месяцев назад

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-12244

11 месяцев назад

An issue has been discovered in access controls could allow users to v ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-1250

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-1250

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-12431

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

CVSS3: 4.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-12431

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

CVSS3: 4.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-12431

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-12380

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

CVSS3: 4.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-12380

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

CVSS3: 4.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-12380

An issue was discovered in GitLab EE/CE affecting all versions startin ...

CVSS3: 4.4
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-12379

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVSS3: 6.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-12379

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVSS3: 6.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-12379

A denial of service vulnerability in GitLab CE/EE affecting all versio ...

CVSS3: 6.5
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-12303

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-12303

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

CVSS3: 6.7
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-12303

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.7
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2024-12292

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-12292

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

CVSS3: 4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-12292

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-12244

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2024-12244

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
debian логотип
CVE-2024-12244

An issue has been discovered in access controls could allow users to v ...

CVSS3: 4.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу