Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2024-10043

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2024-10043

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2024-0861

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-0861

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-0861

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-0456

около 2 лет назад

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-0456

около 2 лет назад

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-0456

около 2 лет назад

An authorization vulnerability exists in GitLab versions 14.0 prior to ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-0410

около 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2024-0410

около 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2024-0410

около 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecti ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2024-0402

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
EPSS: Средний
nvd логотип

CVE-2024-0402

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
EPSS: Средний
debian логотип

CVE-2024-0402

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 9.9
EPSS: Средний
ubuntu логотип

CVE-2024-0231

больше 1 года назад

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2024-0231

больше 1 года назад

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2024-0231

больше 1 года назад

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 pr ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2024-0199

около 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2024-0199

около 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2024-0199

около 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecti ...

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-10043

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS3: 3.1
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-10043

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-0861

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-0861

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-0861

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-0456

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-0456

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-0456

An authorization vulnerability exists in GitLab versions 14.0 prior to ...

CVSS3: 4.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-0410

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-0410

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-0410

An authorization bypass vulnerability was discovered in GitLab affecti ...

CVSS3: 7.7
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-0402

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
41%
Средний
около 2 лет назад
nvd логотип
CVE-2024-0402

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

CVSS3: 9.9
41%
Средний
около 2 лет назад
debian логотип
CVE-2024-0402

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 9.9
41%
Средний
около 2 лет назад
ubuntu логотип
CVE-2024-0231

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

CVSS3: 2.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-0231

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

CVSS3: 2.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-0231

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 pr ...

CVSS3: 2.7
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-0199

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS3: 7.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-0199

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS3: 7.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-0199

An authorization bypass vulnerability was discovered in GitLab affecti ...

CVSS3: 7.7
0%
Низкий
около 2 лет назад

Уязвимостей на страницу