Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2023-5356

около 2 лет назад

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2023-5356

около 2 лет назад

Incorrect authorization checks in GitLab CE/EE from all versions start ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2023-5226

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2023-5226

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2023-5226

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2023-5207

больше 2 лет назад

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2023-5207

больше 2 лет назад

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2023-5207

больше 2 лет назад

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2023-5207

больше 2 лет назад

A vulnerability was discovered in GitLab CE and EE affecting all versi ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2023-5198

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-5198

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-5198

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions prior to ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-5117

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2023-5117

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2023-5117

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions before ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2023-5106

больше 2 лет назад

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2023-5106

больше 2 лет назад

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2023-5106

больше 2 лет назад

An issue has been discovered in Ultimate-licensed GitLab EE affecting ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2023-5061

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-5061

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-5356

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS3: 7.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-5356

Incorrect authorization checks in GitLab CE/EE from all versions start ...

CVSS3: 7.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-5226

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5226

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5226

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5207

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-5207

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5207

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5207

A vulnerability was discovered in GitLab CE and EE affecting all versi ...

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5198

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5198

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5198

An issue has been discovered in GitLab affecting all versions prior to ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5117

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5117

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5117

An issue was discovered in GitLab CE/EE affecting all versions before ...

CVSS3: 3.7
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-5106

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5106

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5106

An issue has been discovered in Ultimate-licensed GitLab EE affecting ...

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-5061

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5061

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу