Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-4143

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-4143

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2022-4143

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2022-4138

около 3 лет назад

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-4138

около 3 лет назад

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2022-4138

около 3 лет назад

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2022-4131

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-4131

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-4131

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-4092

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2022-4092

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2022-4092

около 3 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2022-4054

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-4054

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-4054

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2022-4037

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-4037

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2022-4037

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2022-4007

около 3 лет назад

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-4007

около 3 лет назад

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-4143

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-4143

An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization

CVSS3: 6.4
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-4143

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.4
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-4138

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4138

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4138

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE ...

CVSS3: 6.4
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4131

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4131

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4131

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4092

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

CVSS3: 5.7
5%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4092

An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.

CVSS3: 5.7
5%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4092

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 5.7
5%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4054

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4054

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4054

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.5
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 6.4
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

CVSS3: 6.4
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.4
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-4007

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-4007

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
1%
Низкий
около 3 лет назад

Уязвимостей на страницу