Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2023-3964

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3950

больше 2 лет назад

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-3950

больше 2 лет назад

An information disclosure issue in GitLab EE affecting all versions fr ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2023-3949

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-3949

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-3949

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-3932

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

EPSS: Низкий
nvd логотип

CVE-2023-3932

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2023-3932

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2023-3922

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

CVSS3: 3
EPSS: Низкий
nvd логотип

CVE-2023-3922

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

CVSS3: 3
EPSS: Низкий
debian логотип

CVE-2023-3922

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3
EPSS: Низкий
ubuntu логотип

CVE-2023-3920

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3920

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3920

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-3917

больше 2 лет назад

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3917

больше 2 лет назад

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3917

больше 2 лет назад

Denial of Service in pipelines affecting all versions of Gitlab EE and ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3915

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-3915

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-3964

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3950

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3950

An information disclosure issue in GitLab EE affecting all versions fr ...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3949

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3949

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3949

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-3932

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3932

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3932

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3922

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

CVSS3: 3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3922

An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

CVSS3: 3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3922

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3920

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3920

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3920

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3917

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3917

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3917

Denial of Service in pipelines affecting all versions of Gitlab EE and ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3915

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3915

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу