Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 4 983

Количество 4 983

github логотип

GHSA-pwvw-rggj-f74r

8 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-pwp8-jvcw-f7w4

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-pw3w-gf65-52v7

около 3 лет назад

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

EPSS: Низкий
github логотип

GHSA-pvxf-9mm4-92xf

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-pvq4-gmpq-27p3

11 месяцев назад

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-pvm7-rp3m-8gh2

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-prwp-cpfg-vppq

около 3 лет назад

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

EPSS: Низкий
github логотип

GHSA-prvv-j9vx-7x9q

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

EPSS: Низкий
github логотип

GHSA-prvg-5h5v-3mxw

4 месяца назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-prpj-mw53-gcp4

около 3 лет назад

GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.

EPSS: Низкий
github логотип

GHSA-pqww-m5hf-xxfh

около 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-pqhq-pv8w-43hj

около 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.

EPSS: Низкий
github логотип

GHSA-pqgh-rchr-9hg3

около 1 года назад

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-pq7v-xh7j-pwmx

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 15.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-ppjq-2qhc-pjp7

почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-pmjq-38q6-fxx9

около 2 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-pjvm-3x7g-4998

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.

EPSS: Низкий
github логотип

GHSA-phq7-q979-hvg6

около 3 лет назад

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

EPSS: Низкий
github логотип

GHSA-phjw-j3fx-vxpj

больше 2 лет назад

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-ph8h-4mq7-vw5v

11 месяцев назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pwvw-rggj-f74r

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

CVSS3: 3.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-pwp8-jvcw-f7w4

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

0%
Низкий
около 3 лет назад
github логотип
GHSA-pw3w-gf65-52v7

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

0%
Низкий
около 3 лет назад
github логотип
GHSA-pvxf-9mm4-92xf

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.

CVSS3: 7.3
3%
Низкий
больше 1 года назад
github логотип
GHSA-pvq4-gmpq-27p3

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-pvm7-rp3m-8gh2

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-prwp-cpfg-vppq

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

0%
Низкий
около 3 лет назад
github логотип
GHSA-prvv-j9vx-7x9q

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

0%
Низкий
около 3 лет назад
github логотип
GHSA-prvg-5h5v-3mxw

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-prpj-mw53-gcp4

GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.

0%
Низкий
около 3 лет назад
github логотип
GHSA-pqww-m5hf-xxfh

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-pqhq-pv8w-43hj

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.

0%
Низкий
около 3 лет назад
github логотип
GHSA-pqgh-rchr-9hg3

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

CVSS3: 2.6
0%
Низкий
около 1 года назад
github логотип
GHSA-pq7v-xh7j-pwmx

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 15.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-ppjq-2qhc-pjp7

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVSS3: 3.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-pmjq-38q6-fxx9

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

CVSS3: 8.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-pjvm-3x7g-4998

Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-phq7-q979-hvg6

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

0%
Низкий
около 3 лет назад
github логотип
GHSA-phjw-j3fx-vxpj

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

CVSS3: 9.8
6%
Низкий
больше 2 лет назад
github логотип
GHSA-ph8h-4mq7-vw5v

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

CVSS3: 9.9
0%
Низкий
11 месяцев назад

Уязвимостей на страницу