Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2023-2620

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-2620

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-2620

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2023-2589

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2023-2589

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-2589

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2023-2576

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-2576

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-2576

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-2485

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2023-2485

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2023-2485

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2023-2478

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2023-2478

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2023-2478

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 9.6
EPSS: Низкий
ubuntu логотип

CVE-2023-2442

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Высокий
nvd логотип

CVE-2023-2442

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Высокий
debian логотип

CVE-2023-2442

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
EPSS: Высокий
ubuntu логотип

CVE-2023-2233

больше 2 лет назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-2233

больше 2 лет назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-2620

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2620

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-2620

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-2589

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2589

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2589

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5.9
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2576

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2576

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-2576

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-2485

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2485

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2485

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.4
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2478

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.

CVSS3: 9.6
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2478

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.

CVSS3: 9.6
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2478

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 9.6
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2442

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
84%
Высокий
почти 3 года назад
nvd логотип
CVE-2023-2442

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
84%
Высокий
почти 3 года назад
debian логотип
CVE-2023-2442

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.7
84%
Высокий
почти 3 года назад
ubuntu логотип
CVE-2023-2233

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2233

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу