Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2023-6682

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-6680

больше 2 лет назад

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2023-6680

больше 2 лет назад

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2023-6680

больше 2 лет назад

An improper certificate validation issue in Smartcard authentication i ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2023-6678

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a denial of service using malicious crafted content in a junit test report file.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-6678

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a denial of service using malicious crafted content in a junit test report file.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-6678

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions befor ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-6564

около 2 лет назад

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6564

около 2 лет назад

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6564

около 2 лет назад

An issue has been discovered in GitLab EE Premium and Ultimate affecti ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-6502

почти 2 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-6502

почти 2 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-6502

почти 2 года назад

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-6489

почти 2 года назад

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-6489

почти 2 года назад

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-6489

почти 2 года назад

A denial of service vulnerability was identified in GitLab CE/EE, vers ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-6477

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2023-6477

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2023-6477

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2023-6386

около 1 года назад

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-6682

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-6680

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6680

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6680

An improper certificate validation issue in Smartcard authentication i ...

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-6678

An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a denial of service using malicious crafted content in a junit test report file.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-6678

An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a denial of service using malicious crafted content in a junit test report file.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-6678

An issue has been discovered in GitLab EE affecting all versions befor ...

CVSS3: 4.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-6564

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-6564

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-6564

An issue has been discovered in GitLab EE Premium and Ultimate affecti ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-6502

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-6502

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-6502

A Denial of Service (DoS) condition has been discovered in GitLab CE/E ...

CVSS3: 4.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-6489

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-6489

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-6489

A denial of service vulnerability was identified in GitLab CE/EE, vers ...

CVSS3: 4.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-6477

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-6477

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-6477

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.7
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-6386

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.

CVSS3: 6.5
3%
Низкий
около 1 года назад

Уязвимостей на страницу