Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 332

Количество 5 332

github логотип

GHSA-qfrc-4c6q-334p

12 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-qfpg-mw2p-44hg

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qf2w-qprx-c232

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI-enforced role restrictions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qcrv-74q6-jcj4

больше 3 лет назад

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

EPSS: Низкий
github логотип

GHSA-qcj8-gp4q-v8r2

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

EPSS: Низкий
github логотип

GHSA-qchj-3w44-j257

больше 3 лет назад

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

EPSS: Низкий
github логотип

GHSA-qch9-vmv9-f8v6

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-qccj-j742-ww2r

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-qccf-5wwv-jq8x

5 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-q9g6-jf2g-r26w

больше 3 лет назад

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q9g2-gp7g-r5fj

больше 3 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q99w-5q7g-6x5x

больше 3 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q8qc-382x-cwgc

больше 3 лет назад

Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).

EPSS: Низкий
github логотип

GHSA-q8cg-g95p-qfr2

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-q874-xrmj-fh8q

больше 3 лет назад

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-q84m-97hf-554f

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

EPSS: Низкий
github логотип

GHSA-q7qw-4c2f-p3rj

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

EPSS: Низкий
github логотип

GHSA-q7pq-xhw5-p4xw

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-q7jc-qjq2-4cmx

больше 3 лет назад

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

EPSS: Низкий
github логотип

GHSA-q7hv-qq3g-4grg

почти 3 года назад

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qfrc-4c6q-334p

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVSS3: 4.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-qfpg-mw2p-44hg

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-qf2w-qprx-c232

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI-enforced role restrictions.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-qcrv-74q6-jcj4

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

0%
Низкий
больше 3 лет назад
github логотип
GHSA-qcj8-gp4q-v8r2

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

0%
Низкий
больше 3 лет назад
github логотип
GHSA-qchj-3w44-j257

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-qch9-vmv9-f8v6

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-qccj-j742-ww2r

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-qccf-5wwv-jq8x

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-q9g6-jf2g-r26w

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q9g2-gp7g-r5fj

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q99w-5q7g-6x5x

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-q8qc-382x-cwgc

Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q8cg-g95p-qfr2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction.

CVSS3: 6.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-q874-xrmj-fh8q

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q84m-97hf-554f

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q7qw-4c2f-p3rj

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q7pq-xhw5-p4xw

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q7jc-qjq2-4cmx

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q7hv-qq3g-4grg

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 6.1
1%
Низкий
почти 3 года назад

Уязвимостей на страницу