Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2023-6386

около 1 года назад

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6386

около 1 года назад

A denial of service vulnerability was identified in GitLab CE/EE, affe ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-6371

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2023-6371

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2023-6371

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2023-6195

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2023-6195

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2023-6195

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2023-6159

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6159

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6159

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-6051

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2023-6051

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2023-6051

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2023-6033

больше 2 лет назад

Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2023-6033

больше 2 лет назад

Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2023-6033

больше 2 лет назад

Improper neutralization of input in Jira integration configuration in ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2023-5995

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2023-5995

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2023-5995

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-6386

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.

CVSS3: 6.5
3%
Низкий
около 1 года назад
debian логотип
CVE-2023-6386

A denial of service vulnerability was identified in GitLab CE/EE, affe ...

CVSS3: 6.5
3%
Низкий
около 1 года назад
ubuntu логотип
CVE-2023-6371

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-6371

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-6371

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 8.7
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-6195

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
0%
Низкий
около 1 года назад
nvd логотип
CVE-2023-6195

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
0%
Низкий
около 1 года назад
debian логотип
CVE-2023-6195

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 2.6
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2023-6159

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-6159

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-6159

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-6051

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6051

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6051

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-6033

Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.

CVSS3: 8.7
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6033

Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.

CVSS3: 8.7
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6033

Improper neutralization of input in Jira integration configuration in ...

CVSS3: 8.7
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5995

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5995

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5995

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу