Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2023-0050

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
EPSS: Средний
debian логотип

CVE-2023-0050

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 8.7
EPSS: Средний
ubuntu логотип

CVE-2023-0042

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-0042

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-0042

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2022-4462

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2022-4462

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2022-4462

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2022-4376

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-4376

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-4376

почти 3 года назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-4365

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-4365

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-4365

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-4343

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2022-4343

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2022-4342

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-4342

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-4342

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-43411

больше 3 лет назад

Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-0050

An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVSS3: 8.7
65%
Средний
около 3 лет назад
debian логотип
CVE-2023-0050

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 8.7
65%
Средний
около 3 лет назад
ubuntu логотип
CVE-2023-0042

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-0042

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-0042

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.1
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4462

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4462

An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.

CVSS3: 5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4462

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4376

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-4376

An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-4376

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 3.1
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-4365

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4365

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4365

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4343

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

CVSS3: 5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-4343

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-4342

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 5.5
2%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4342

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook.

CVSS3: 5.5
2%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4342

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
2%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-43411

Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу