Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-3330

больше 3 лет назад

It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3330

больше 3 лет назад

It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3330

больше 3 лет назад

It was possible for a guest user to read a todo targeting an inaccessi ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3325

больше 3 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2022-3325

больше 3 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2022-3325

больше 3 лет назад

Improper access control in the GitLab CE/EE API affecting all versions ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2022-3293

больше 3 лет назад

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-3293

больше 3 лет назад

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-3293

больше 3 лет назад

Email addresses were leaked in WebHook logs in GitLab EE affecting all ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3291

больше 3 лет назад

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-3291

больше 3 лет назад

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-3291

больше 3 лет назад

Serialization of sensitive data in GitLab EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3288

больше 3 лет назад

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-3288

больше 3 лет назад

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-3288

больше 3 лет назад

A branch/tag name confusion in GitLab CE/EE affecting all versions pri ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3286

больше 3 лет назад

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-3286

больше 3 лет назад

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-3286

больше 3 лет назад

Lack of IP address checking in GitLab EE affecting all versions from 1 ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3285

больше 3 лет назад

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-3285

больше 3 лет назад

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-3330

It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3330

It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3330

It was possible for a guest user to read a todo targeting an inaccessi ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3325

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3325

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3325

Improper access control in the GitLab CE/EE API affecting all versions ...

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3293

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3293

Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3293

Email addresses were leaked in WebHook logs in GitLab EE affecting all ...

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3291

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3291

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3291

Serialization of sensitive data in GitLab EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3288

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3288

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3288

A branch/tag name confusion in GitLab CE/EE affecting all versions pri ...

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3286

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3286

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3286

Lack of IP address checking in GitLab EE affecting all versions from 1 ...

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3285

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3285

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу