Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2023-2013

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2023-2013

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2023-2013

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2023-2001

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-2001

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-2001

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-1965

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2023-1965

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2023-1936

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2023-1936

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2023-1936

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2023-1836

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2023-1836

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2023-1836

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab affecting a ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2023-1825

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-1825

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-1825

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-1787

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-1787

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-1787

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-2013

An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 2.6
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2013

An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS3: 2.6
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2013

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 2.6
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-2001

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-2001

An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-2001

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.3
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-1965

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-1965

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 6.8
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-1936

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-1936

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-1936

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-1836

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVSS3: 4.4
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-1836

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVSS3: 4.4
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-1836

A cross-site scripting issue has been discovered in GitLab affecting a ...

CVSS3: 4.4
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-1825

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-1825

An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-1825

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.1
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-1787

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-1787

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-1787

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу