Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2023-7045

почти 2 года назад

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-7045

почти 2 года назад

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-7045

почти 2 года назад

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 be ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2023-7028

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
EPSS: Критический
nvd логотип

CVE-2023-7028

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
EPSS: Критический
debian логотип

CVE-2023-7028

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 10
EPSS: Критический
ubuntu логотип

CVE-2023-6955

около 2 лет назад

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2023-6955

около 2 лет назад

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2023-6955

около 2 лет назад

A missing authorization check vulnerability exists in GitLab Remote De ...

CVSS3: 6.6
EPSS: Низкий
ubuntu логотип

CVE-2023-6840

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2023-6840

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2023-6840

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2023-6736

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6736

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6736

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-6688

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6688

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6688

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-6682

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6682

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-7045

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

CVSS3: 5.4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-7045

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

CVSS3: 5.4
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-7045

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 be ...

CVSS3: 5.4
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
94%
Критический
около 2 лет назад
nvd логотип
CVE-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS3: 10
94%
Критический
около 2 лет назад
debian логотип
CVE-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 10
94%
Критический
около 2 лет назад
ubuntu логотип
CVE-2023-6955

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-6955

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-6955

A missing authorization check vulnerability exists in GitLab Remote De ...

CVSS3: 6.6
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-6840

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-6840

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-6840

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.7
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-6736

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-6736

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-6736

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-6688

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-6688

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-6688

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-6682

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-6682

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу