Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-qx55-2cp2-7ppq

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-qwxw-v6wx-qh2q

почти 3 года назад

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-qw5x-x275-9wwh

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qvvw-3v9r-73ph

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-qvhh-qrj8-5g7c

больше 1 года назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qvh8-3fcf-c54f

почти 4 года назад

Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

EPSS: Низкий
github логотип

GHSA-qvg5-w5f4-rcwh

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-qv6p-pfj5-mhj9

16 дней назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-qv5m-w8c2-586r

почти 4 года назад

GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-qrrr-vqv8-9hcw

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qrp8-hgrf-wv83

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-qrcv-45vg-jfwm

почти 4 года назад

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

EPSS: Низкий
github логотип

GHSA-qr9v-c6jg-wx28

6 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-qp45-rpvf-p5q7

почти 4 года назад

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

EPSS: Низкий
github логотип

GHSA-qmqh-cxhx-r5v4

почти 4 года назад

GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

EPSS: Низкий
github логотип

GHSA-qjj8-rghq-cx4f

почти 4 года назад

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qjfq-84f6-v57x

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

EPSS: Низкий
github логотип

GHSA-qj9x-qgqc-v252

почти 4 года назад

GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace

EPSS: Низкий
github логотип

GHSA-qj8w-vx7m-776m

почти 4 года назад

An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-qhv6-q9x7-ggmg

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qx55-2cp2-7ppq

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

CVSS3: 3.1
5%
Низкий
почти 3 года назад
github логотип
GHSA-qwxw-v6wx-qh2q

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.

CVSS3: 5.3
2%
Низкий
почти 3 года назад
github логотип
GHSA-qw5x-x275-9wwh

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-qvvw-3v9r-73ph

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
0%
Низкий
около 1 года назад
github логотип
GHSA-qvhh-qrj8-5g7c

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-qvh8-3fcf-c54f

Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

0%
Низкий
почти 4 года назад
github логотип
GHSA-qvg5-w5f4-rcwh

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-qv6p-pfj5-mhj9

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.

CVSS3: 8.7
0%
Низкий
16 дней назад
github логотип
GHSA-qv5m-w8c2-586r

GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-qrrr-vqv8-9hcw

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-qrp8-hgrf-wv83

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-qrcv-45vg-jfwm

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

0%
Низкий
почти 4 года назад
github логотип
GHSA-qr9v-c6jg-wx28

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.

CVSS3: 7.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-qp45-rpvf-p5q7

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-qmqh-cxhx-r5v4

GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

0%
Низкий
почти 4 года назад
github логотип
GHSA-qjj8-rghq-cx4f

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-qjfq-84f6-v57x

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

0%
Низкий
почти 4 года назад
github логотип
GHSA-qj9x-qgqc-v252

GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace

0%
Низкий
почти 4 года назад
github логотип
GHSA-qj8w-vx7m-776m

An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-qhv6-q9x7-ggmg

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.

CVSS3: 6.5
0%
Низкий
9 месяцев назад

Уязвимостей на страницу