Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2023-2233

больше 2 лет назад

An improper authorization issue has been discovered in GitLab CE/EE af ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-2232

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-2232

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-2232

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-2200

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

CVSS3: 4.1
EPSS: Низкий
nvd логотип

CVE-2023-2200

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

CVSS3: 4.1
EPSS: Низкий
debian логотип

CVE-2023-2200

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.1
EPSS: Низкий
ubuntu логотип

CVE-2023-2199

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-2199

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-2199

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-2198

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-2198

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-2198

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-2190

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-2190

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-2190

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-2182

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thus leading to privilege escalation for those users.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2023-2182

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2023-2181

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2023-2181

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-2233

An improper authorization issue has been discovered in GitLab CE/EE af ...

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-2232

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

CVSS3: 6.5
2%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2232

An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix

CVSS3: 6.5
2%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2232

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
2%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2200

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

CVSS3: 4.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2200

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

CVSS3: 4.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-2200

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.1
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-2199

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
2%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2199

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
2%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2199

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
2%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2198

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2198

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2198

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2190

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2190

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-2190

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2182

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thus leading to privilege escalation for those users.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2182

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.8
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2181

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2181

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.

CVSS3: 6.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу