Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2023-3509

около 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2023-3509

около 2 лет назад

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2023-3509

около 2 лет назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2023-3500

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2023-3500

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

EPSS: Низкий
nvd логотип

CVE-2023-3500

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2023-3500

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2023-3484

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2023-3484

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2023-3444

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2023-3444

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2023-3444

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2023-3443

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-3443

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-3443

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-3441

больше 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2023-3441

больше 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2023-3441

больше 1 года назад

An issue has been discovered in GitLab EE/CE affecting all versions st ...

CVSS3: 6.6
EPSS: Низкий
ubuntu логотип

CVE-2023-3424

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-3424

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-3509

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-3509

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVSS3: 3.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-3509

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 3.7
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-3500

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-3500

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3500

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3500

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3484

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.

CVSS3: 8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3484

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 8
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3444

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3444

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3444

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3443

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3443

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3443

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3441

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVSS3: 6.6
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-3441

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVSS3: 6.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-3441

An issue has been discovered in GitLab EE/CE affecting all versions st ...

CVSS3: 6.6
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-3424

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3424

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу