Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-qh9v-hc8g-m9wx

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).

EPSS: Низкий
github логотип

GHSA-qgwf-v74m-338m

около 4 лет назад

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-qgvm-92m2-j87g

около 4 лет назад

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qgpv-xwh3-9v79

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qg3j-4m32-rxh8

около 4 лет назад

A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.

EPSS: Низкий
github логотип

GHSA-qfrc-4c6q-334p

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-qfqq-fmmm-p2r3

23 дня назад

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to modify group-level settings beyond their intended permissions due to improper authorization controls.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-qfpg-mw2p-44hg

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qfj5-c4hr-4gr8

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthenticated user to cause denial of service by sending specially crafted requests to a CI jobs API endpoint.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-qf2w-qprx-c232

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI-enforced role restrictions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qcrv-74q6-jcj4

около 4 лет назад

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

EPSS: Низкий
github логотип

GHSA-qcj8-gp4q-v8r2

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

EPSS: Низкий
github логотип

GHSA-qchj-3w44-j257

около 4 лет назад

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

EPSS: Низкий
github логотип

GHSA-qch9-vmv9-f8v6

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-qccj-j742-ww2r

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-qccf-5wwv-jq8x

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-q9qr-p283-j9rm

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resource allocation limits in the GraphQL API.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q9j8-24p8-jq8j

около 2 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-q9g6-jf2g-r26w

почти 4 года назад

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q9g2-gp7g-r5fj

около 4 лет назад

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qh9v-hc8g-m9wx

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).

1%
Низкий
около 4 лет назад
github логотип
GHSA-qgwf-v74m-338m

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

CVSS3: 6.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-qgvm-92m2-j87g

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-qgpv-xwh3-9v79

An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-qg3j-4m32-rxh8

A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.

3%
Низкий
около 4 лет назад
github логотип
GHSA-qfrc-4c6q-334p

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-qfqq-fmmm-p2r3

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to modify group-level settings beyond their intended permissions due to improper authorization controls.

CVSS3: 2.7
0%
Низкий
23 дня назад
github логотип
GHSA-qfpg-mw2p-44hg

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-qfj5-c4hr-4gr8

GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthenticated user to cause denial of service by sending specially crafted requests to a CI jobs API endpoint.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-qf2w-qprx-c232

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI-enforced role restrictions.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-qcrv-74q6-jcj4

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

1%
Низкий
около 4 лет назад
github логотип
GHSA-qcj8-gp4q-v8r2

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

1%
Низкий
около 4 лет назад
github логотип
GHSA-qchj-3w44-j257

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qch9-vmv9-f8v6

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

CVSS3: 5.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-qccj-j742-ww2r

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

CVSS3: 5.7
1%
Низкий
около 3 лет назад
github логотип
GHSA-qccf-5wwv-jq8x

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

CVSS3: 5.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-q9qr-p283-j9rm

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resource allocation limits in the GraphQL API.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-q9j8-24p8-jq8j

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.

CVSS3: 7.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-q9g6-jf2g-r26w

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-q9g2-gp7g-r5fj

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу