Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2023-5963

больше 2 лет назад

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-5963

больше 2 лет назад

An issue has been discovered in GitLab EE with Advanced Search affecti ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-5933

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2023-5933

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2023-5933

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions af ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2023-5831

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2023-5831

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2023-5831

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2023-5825

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-5825

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-5825

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-5612

около 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2023-5612

около 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2023-5612

около 2 лет назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2023-5600

10 месяцев назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-5600

10 месяцев назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-5512

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2023-5512

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2023-5512

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2023-5356

около 2 лет назад

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-5963

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5963

An issue has been discovered in GitLab EE with Advanced Search affecti ...

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5933

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
4%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-5933

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS3: 6.4
4%
Низкий
около 2 лет назад
debian логотип
CVE-2023-5933

An issue has been discovered in GitLab CE/EE affecting all versions af ...

CVSS3: 6.4
4%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-5831

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5831

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5831

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5825

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5825

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5825

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5612

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
26%
Средний
около 2 лет назад
nvd логотип
CVE-2023-5612

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVSS3: 5.3
26%
Средний
около 2 лет назад
debian логотип
CVE-2023-5612

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 5.3
26%
Средний
около 2 лет назад
nvd логотип
CVE-2023-5600

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.

CVSS3: 3.1
0%
Низкий
10 месяцев назад
debian логотип
CVE-2023-5600

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2023-5512

An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5512

An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5512

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5356

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS3: 7.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу