Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2022-3285

больше 3 лет назад

Bypass of healthcheck endpoint allow list affecting all versions from ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3283

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-3283

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-3283

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3280

больше 3 лет назад

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-3280

больше 3 лет назад

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-3280

больше 3 лет назад

An open redirect in GitLab CE/EE affecting all versions from 10.1 prio ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3279

больше 3 лет назад

An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2022-3279

больше 3 лет назад

An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2022-3279

больше 3 лет назад

An unhandled exception in job log parsing in GitLab CE/EE affecting al ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2022-3265

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Средний
nvd логотип

CVE-2022-3265

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Средний
debian логотип

CVE-2022-3265

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
EPSS: Средний
nvd логотип

CVE-2022-30955

почти 4 года назад

Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3067

больше 3 лет назад

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-3067

больше 3 лет назад

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-3067

больше 3 лет назад

An issue has been discovered in the Import functionality of GitLab CE/ ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3066

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-3066

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-3066

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-3285

Bypass of healthcheck endpoint allow list affecting all versions from ...

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3283

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3283

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3283

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3280

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3280

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3280

An open redirect in GitLab CE/EE affecting all versions from 10.1 prio ...

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3279

An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3279

An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3279

An unhandled exception in job log parsing in GitLab CE/EE affecting al ...

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3265

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
18%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-3265

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
18%
Средний
больше 3 лет назад
debian логотип
CVE-2022-3265

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
18%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-30955

Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-3067

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3067

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3067

An issue has been discovered in the Import functionality of GitLab CE/ ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3066

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3066

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3066

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу