Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 332

Количество 5 332

github логотип

GHSA-q7f8-fr48-qw7g

почти 4 года назад

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-q768-3m4h-qj2j

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-q757-g3qv-54vf

почти 4 года назад

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q6vr-pm5m-w6c6

больше 3 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

EPSS: Низкий
github логотип

GHSA-q6vm-3q95-jvvp

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-q6mw-555r-hgcg

4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim's project.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-q6jf-84qm-cj59

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

EPSS: Низкий
github логотип

GHSA-q6h4-g972-8qqw

больше 3 лет назад

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

EPSS: Низкий
github логотип

GHSA-q656-cxxx-f8h7

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q5w6-p37j-cwr4

больше 3 лет назад

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

EPSS: Низкий
github логотип

GHSA-q5jf-8f55-j92v

больше 3 лет назад

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

EPSS: Низкий
github логотип

GHSA-q5g8-585j-mh24

больше 3 лет назад

GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.

EPSS: Низкий
github логотип

GHSA-q49w-v89m-366g

больше 3 лет назад

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

EPSS: Низкий
github логотип

GHSA-q477-jxcv-9pxw

больше 3 лет назад

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

EPSS: Низкий
github логотип

GHSA-q439-vprm-5c8j

больше 3 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-q3qh-rxpm-hmc7

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

EPSS: Низкий
github логотип

GHSA-q35c-75fc-6v95

около 3 лет назад

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q2f3-hg8j-4wcc

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-q297-5xx3-gw53

больше 3 лет назад

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

EPSS: Низкий
github логотип

GHSA-q28r-ggr6-763f

больше 1 года назад

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-q7f8-fr48-qw7g

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 9.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-q768-3m4h-qj2j

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-q757-g3qv-54vf

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-q6vr-pm5m-w6c6

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q6vm-3q95-jvvp

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q6mw-555r-hgcg

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim's project.

CVSS3: 3.5
0%
Низкий
4 месяца назад
github логотип
GHSA-q6jf-84qm-cj59

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q6h4-g972-8qqw

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q656-cxxx-f8h7

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-q5w6-p37j-cwr4

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q5jf-8f55-j92v

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q5g8-585j-mh24

GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q49w-v89m-366g

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q477-jxcv-9pxw

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q439-vprm-5c8j

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q3qh-rxpm-hmc7

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q35c-75fc-6v95

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-q2f3-hg8j-4wcc

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-q297-5xx3-gw53

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

0%
Низкий
больше 3 лет назад
github логотип
GHSA-q28r-ggr6-763f

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу