Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2023-3363

больше 2 лет назад

An information disclosure issue in Gitlab CE/EE affecting all versions ...

CVSS3: 3.9
EPSS: Низкий
ubuntu логотип

CVE-2023-3362

больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-3362

больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-3362

больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2023-3246

больше 2 лет назад

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-3246

больше 2 лет назад

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-3246

больше 2 лет назад

An issue has been discovered in GitLab EE/CE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-3210

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-3210

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-3210

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-3205

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-3205

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-3205

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-3115

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-3115

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions affec ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-3102

больше 2 лет назад

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-3102

больше 2 лет назад

A sensitive information leak issue has been discovered in GitLab EE af ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2023-2825

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CVSS3: 10
EPSS: Критический
nvd логотип

CVE-2023-2825

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CVSS3: 10
EPSS: Критический
debian логотип

CVE-2023-2825

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting only version 16 ...

CVSS3: 10
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-3363

An information disclosure issue in Gitlab CE/EE affecting all versions ...

CVSS3: 3.9
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3362

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3362

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3362

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3246

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3246

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3246

An issue has been discovered in GitLab EE/CE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3210

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3210

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3210

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-3205

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3205

An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3205

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3115

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3115

An issue has been discovered in GitLab EE affecting all versions affec ...

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-3102

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-3102

A sensitive information leak issue has been discovered in GitLab EE af ...

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-2825

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CVSS3: 10
92%
Критический
почти 3 года назад
nvd логотип
CVE-2023-2825

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CVSS3: 10
92%
Критический
почти 3 года назад
debian логотип
CVE-2023-2825

An issue has been discovered in GitLab CE/EE affecting only version 16 ...

CVSS3: 10
92%
Критический
почти 3 года назад

Уязвимостей на страницу