Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2023-1084

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2023-1084

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2023-1072

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-1072

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-1072

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-1071

около 3 лет назад

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-1071

около 3 лет назад

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-1071

около 3 лет назад

An issue has been discovered in GitLab affecting all versions from 15. ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-0989

больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-0989

больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-0989

больше 2 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-0921

почти 3 года назад

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 4.3
EPSS: Средний
nvd логотип

CVE-2023-0921

почти 3 года назад

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 4.3
EPSS: Средний
debian логотип

CVE-2023-0921

почти 3 года назад

A lack of length validation in GitLab CE/EE affecting all versions fro ...

CVSS3: 4.3
EPSS: Средний
ubuntu логотип

CVE-2023-0838

около 3 лет назад

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-0838

около 3 лет назад

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-0838

около 3 лет назад

An issue has been discovered in GitLab affecting versions starting fro ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-0805

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from the public group by the owner.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2023-0805

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2023-0756

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-1084

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.

CVSS3: 2.7
4%
Низкий
около 3 лет назад
debian логотип
CVE-2023-1084

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 2.7
4%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-1072

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-1072

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-1072

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-1071

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

CVSS3: 3.1
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-1071

An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.

CVSS3: 3.1
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-1071

An issue has been discovered in GitLab affecting all versions from 15. ...

CVSS3: 3.1
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-0989

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-0989

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-0989

An information disclosure issue in GitLab CE/EE affecting all versions ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-0921

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 4.3
21%
Средний
почти 3 года назад
nvd логотип
CVE-2023-0921

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 4.3
21%
Средний
почти 3 года назад
debian логотип
CVE-2023-0921

A lack of length validation in GitLab CE/EE affecting all versions fro ...

CVSS3: 4.3
21%
Средний
почти 3 года назад
ubuntu логотип
CVE-2023-0838

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-0838

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-0838

An issue has been discovered in GitLab affecting versions starting fro ...

CVSS3: 5.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-0805

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from the public group by the owner.

CVSS3: 4.9
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-0805

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.9
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-0756

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVSS3: 4.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу