Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2024-11274

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-11129

12 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2024-11129

12 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2024-10925

около 1 года назад

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-10925

около 1 года назад

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-1066

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-1066

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-1066

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-10383

около 1 года назад

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-10383

около 1 года назад

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2024-10307

около 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-10307

около 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-10307

около 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions fr ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-10240

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-10240

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-10240

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-10219

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10219

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10219

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-10043

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2024-11274

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 8.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-11129

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."

CVSS3: 6.3
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-11129

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.3
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-10925

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML

CVSS3: 5.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-10925

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to ...

CVSS3: 5.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-1066

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

CVSS3: 6.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-1066

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-1066

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-10383

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS3: 8.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-10383

An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE

CVSS3: 8.7
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-10307

An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.

CVSS3: 4.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-10307

An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.

CVSS3: 4.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-10307

An issue has been discovered in GitLab EE/CE affecting all versions fr ...

CVSS3: 4.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-10240

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-10240

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-10240

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-10219

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-10219

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-10219

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2024-10043

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS3: 3.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу