Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2022-3759

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. An attacker may upload a crafted CI job artifact zip file in a project that uses dynamic child pipelines and make a sidekiq job allocate a lot of memory. In GitLab instances where Sidekiq is memory-limited, this may cause Denial of Service.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3759

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3758

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-3758

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-3758

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-3740

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-3740

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-3740

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3726

больше 3 лет назад

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2022-3726

больше 3 лет назад

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2022-3726

больше 3 лет назад

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2022-3706

больше 3 лет назад

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-3706

больше 3 лет назад

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-3706

больше 3 лет назад

Improper authorization in GitLab CE/EE affecting all versions from 7.1 ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-3639

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3639

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3639

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3613

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2022-3613

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2022-3613

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3759

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. An attacker may upload a crafted CI job artifact zip file in a project that uses dynamic child pipelines and make a sidekiq job allocate a lot of memory. In GitLab instances where Sidekiq is memory-limited, this may cause Denial of Service.

CVSS3: 4.3
2%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3759

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
2%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-3758

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-3758

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3758

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-3740

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .

CVSS3: 6.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-3740

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .

CVSS3: 6.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3740

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-3726

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3726

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3726

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all ...

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3706

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3706

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3706

Improper authorization in GitLab CE/EE affecting all versions from 7.1 ...

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3639

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3639

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3639

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3613

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

CVSS3: 5.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-3613

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service.

CVSS3: 5.8
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3613

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 5.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу