Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2023-1279

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2023-1265

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-1265

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-1265

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2023-1210

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2023-1210

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

EPSS: Низкий
nvd логотип

CVE-2023-1210

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-1210

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-1204

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-1204

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-1204

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-1178

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2023-1178

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2023-1178

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2023-1167

около 3 лет назад

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-1167

около 3 лет назад

Improper authorization in Gitlab EE affecting all versions from 12.3.0 ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2023-1098

около 3 лет назад

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2023-1098

около 3 лет назад

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2023-1098

около 3 лет назад

An information disclosure vulnerability has been discovered in GitLab ...

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2023-1084

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-1279

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-1265

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-1265

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-1265

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-1210

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-1210

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-1210

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-1210

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-1204

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-1204

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-1204

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-1178

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVSS3: 5.7
4%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-1178

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVSS3: 5.7
4%
Низкий
почти 3 года назад
debian логотип
CVE-2023-1178

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.7
4%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-1167

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-1167

Improper authorization in Gitlab EE affecting all versions from 12.3.0 ...

CVSS3: 5.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-1098

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

CVSS3: 5.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-1098

An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.

CVSS3: 5.8
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-1098

An information disclosure vulnerability has been discovered in GitLab ...

CVSS3: 5.8
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-1084

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
4%
Низкий
около 3 лет назад

Уязвимостей на страницу