Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2023-5061

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-5009

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2023-5009

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2023-4912

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2023-4912

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2023-4912

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2023-4895

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-4895

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-4895

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-4812

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2023-4812

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2023-4812

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2023-4700

больше 2 лет назад

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2023-4700

больше 2 лет назад

An authorization issue affecting GitLab EE affecting all versions from ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2023-4658

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-4658

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-4658

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-4647

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-4647

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-4647

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-5061

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-5009

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5009

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-4912

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4912

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4912

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-4895

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects

CVSS3: 4.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-4895

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects

CVSS3: 4.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-4895

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-4812

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-4812

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

CVSS3: 7.6
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-4812

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 7.6
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-4700

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4700

An authorization issue affecting GitLab EE affecting all versions from ...

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-4658

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4658

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4658

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-4647

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4647

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4647

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу