Количество 5 545
Количество 5 545
CVE-2023-3914
A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.
CVE-2023-3914
A business logic error in GitLab EE affecting all versions prior to 16 ...
CVE-2023-3909
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.
CVE-2023-3909
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.
CVE-2023-3909
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2023-3907
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
CVE-2023-3907
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
CVE-2023-3907
A privilege escalation vulnerability in GitLab EE affecting all versio ...
CVE-2023-3906
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.
CVE-2023-3906
An input validation issue in the asset proxy in GitLab EE, affecting a ...
CVE-2023-3904
An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.
CVE-2023-3904
An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.
CVE-2023-3904
An issue has been discovered in GitLab EE affecting all versions start ...
CVE-2023-3900
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.
CVE-2023-3900
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.
CVE-2023-3900
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.
CVE-2023-3900
An issue has been discovered in GitLab CE/EE affecting all versions st ...
CVE-2023-3511
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.
CVE-2023-3511
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.
CVE-2023-3511
An issue has been discovered in GitLab EE affecting all versions start ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-3914 A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3914 A business logic error in GitLab EE affecting all versions prior to 16 ... | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3909 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3909 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3909 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3907 A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3907 A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3907 A privilege escalation vulnerability in GitLab EE affecting all versio ... | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3906 An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy. | CVSS3: 3.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3906 An input validation issue in the asset proxy in GitLab EE, affecting a ... | CVSS3: 3.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3904 An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3904 An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3904 An issue has been discovered in GitLab EE affecting all versions start ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3900 An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3900 An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load. | 0% Низкий | больше 2 лет назад | ||
CVE-2023-3900 An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3900 An issue has been discovered in GitLab CE/EE affecting all versions st ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3511 An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of. | CVSS3: 2 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3511 An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of. | CVSS3: 2 | 0% Низкий | больше 2 лет назад | |
CVE-2023-3511 An issue has been discovered in GitLab EE affecting all versions start ... | CVSS3: 2 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу