Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2023-2181

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2023-2164

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVSS3: 5.4
EPSS: Средний
redhat логотип

CVE-2023-2164

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

EPSS: Средний
nvd логотип

CVE-2023-2164

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVSS3: 5.4
EPSS: Средний
debian логотип

CVE-2023-2164

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
EPSS: Средний
ubuntu логотип

CVE-2023-2132

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-2132

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-2132

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-2069

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2023-2069

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2023-2069

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2023-2030

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2023-2030

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2023-2030

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2023-2022

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-2022

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-2022

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-2015

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2023-2015

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2023-2015

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-2181

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 6.3
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2164

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVSS3: 5.4
52%
Средний
больше 2 лет назад
redhat логотип
CVE-2023-2164

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

52%
Средний
больше 2 лет назад
nvd логотип
CVE-2023-2164

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVSS3: 5.4
52%
Средний
больше 2 лет назад
debian логотип
CVE-2023-2164

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
52%
Средний
больше 2 лет назад
ubuntu логотип
CVE-2023-2132

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2132

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2132

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2069

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2069

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2069

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.4
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2030

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-2030

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-2030

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 3.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-2022

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2022

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-2022

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-2015

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 4.4
8%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2015

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 4.4
8%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2015

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.4
8%
Низкий
почти 3 года назад

Уязвимостей на страницу