Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-4335

около 3 лет назад

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-4335

около 3 лет назад

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-4335

около 3 лет назад

A blind SSRF vulnerability was identified in all versions of GitLab EE ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-4331

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2022-4331

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2022-4289

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-4289

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2022-4289

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2022-4255

около 3 лет назад

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-4255

около 3 лет назад

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-4255

около 3 лет назад

An info leak issue was identified in all versions of GitLab EE from 13 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-4205

около 3 лет назад

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2022-4205

около 3 лет назад

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2022-4205

около 3 лет назад

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a ...

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2022-4201

около 3 лет назад

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-4201

около 3 лет назад

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-4201

около 3 лет назад

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-4167

около 3 лет назад

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-4167

около 3 лет назад

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-4167

около 3 лет назад

Incorrect Authorization check affecting all versions of GitLab EE from ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-4335

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4335

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4335

A blind SSRF vulnerability was identified in all versions of GitLab EE ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4331

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

CVSS3: 5.7
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4331

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5.7
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4289

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 6.4
2%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4289

An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users.

CVSS3: 6.4
2%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4289

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.4
2%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4255

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4255

An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4255

An info leak issue was identified in all versions of GitLab EE from 13 ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4205

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

CVSS3: 6.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4205

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

CVSS3: 6.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4205

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a ...

CVSS3: 6.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4201

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4201

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4201

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, ...

CVSS3: 3.5
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4167

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4167

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4167

Incorrect Authorization check affecting all versions of GitLab EE from ...

CVSS3: 5.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу