Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2023-3914

больше 2 лет назад

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-3914

больше 2 лет назад

A business logic error in GitLab EE affecting all versions prior to 16 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2023-3909

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3909

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3909

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-3907

больше 2 лет назад

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2023-3907

больше 2 лет назад

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2023-3907

больше 2 лет назад

A privilege escalation vulnerability in GitLab EE affecting all versio ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2023-3906

больше 2 лет назад

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2023-3906

больше 2 лет назад

An input validation issue in the asset proxy in GitLab EE, affecting a ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2023-3904

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3904

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3904

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-3900

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2023-3900

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

EPSS: Низкий
nvd логотип

CVE-2023-3900

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3900

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-3511

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.

CVSS3: 2
EPSS: Низкий
nvd логотип

CVE-2023-3511

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.

CVSS3: 2
EPSS: Низкий
debian логотип

CVE-2023-3511

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-3914

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3914

A business logic error in GitLab EE affecting all versions prior to 16 ...

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3909

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3909

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3909

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3907

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3907

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3907

A privilege escalation vulnerability in GitLab EE affecting all versio ...

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3906

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3906

An input validation issue in the asset proxy in GitLab EE, affecting a ...

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3904

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3904

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3904

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3900

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-3900

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3900

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3900

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3511

An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.

CVSS3: 2
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3511

An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.

CVSS3: 2
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3511

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 2
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу