Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2022-3478

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-34777

почти 4 года назад

Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 5.4
EPSS: Средний
ubuntu логотип

CVE-2022-3413

больше 3 лет назад

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3413

больше 3 лет назад

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3413

больше 3 лет назад

Incorrect authorization during display of Audit Events in GitLab EE af ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3411

около 3 лет назад

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-3411

около 3 лет назад

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-3411

около 3 лет назад

A lack of length validation in GitLab CE/EE affecting all versions fro ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3381

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3381

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3381

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3375

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-3375

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-3375

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-3351

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3351

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3351

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3331

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-3331

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-3331

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-3478

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-34777

Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 5.4
25%
Средний
почти 4 года назад
ubuntu логотип
CVE-2022-3413

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3413

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3413

Incorrect authorization during display of Audit Events in GitLab EE af ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3411

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 6.5
3%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-3411

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 6.5
3%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3411

A lack of length validation in GitLab CE/EE affecting all versions fro ...

CVSS3: 6.5
3%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-3381

An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites

CVSS3: 4.3
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-3381

An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites

CVSS3: 4.3
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3381

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-3375

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.1
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-3375

An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private.

CVSS3: 3.1
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3375

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-3351

An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3351

An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3351

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3331

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3331

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3331

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу