Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2023-0756

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2023-0756

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2023-0632

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2023-0632

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

EPSS: Низкий
nvd логотип

CVE-2023-0632

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-0632

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-0523

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 5.4
EPSS: Средний
nvd логотип

CVE-2023-0523

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 5.4
EPSS: Средний
debian логотип

CVE-2023-0523

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
EPSS: Средний
ubuntu логотип

CVE-2023-0518

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-0518

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-0518

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-0508

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-0508

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-0508

почти 3 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2023-0485

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-0485

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-0485

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-0483

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-0483

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-0756

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-0756

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.8
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-0632

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-0632

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-0632

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-0632

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-0523

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 5.4
17%
Средний
около 3 лет назад
nvd логотип
CVE-2023-0523

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 5.4
17%
Средний
около 3 лет назад
debian логотип
CVE-2023-0523

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
17%
Средний
около 3 лет назад
ubuntu логотип
CVE-2023-0518

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.

CVSS3: 4.3
2%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-0518

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.

CVSS3: 4.3
2%
Низкий
около 3 лет назад
debian логотип
CVE-2023-0518

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
2%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-0508

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

CVSS3: 3.1
4%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-0508

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API.

CVSS3: 3.1
4%
Низкий
почти 3 года назад
debian логотип
CVE-2023-0508

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
4%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-0485

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-0485

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-0485

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-0483

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-0483

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу