Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-3060

больше 3 лет назад

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2022-3060

больше 3 лет назад

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-3060

больше 3 лет назад

Improper control of a resource identifier in Error Tracking in GitLab ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3031

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2022-3031

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2022-3031

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2022-3030

больше 3 лет назад

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-3030

больше 3 лет назад

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-3030

больше 3 лет назад

An improper access control issue in GitLab CE/EE affecting all version ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-3018

больше 3 лет назад

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2022-3018

больше 3 лет назад

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2022-3018

больше 3 лет назад

An information disclosure vulnerability in GitLab CE/EE affecting all ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2022-2992

больше 3 лет назад

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS3: 9.9
EPSS: Критический
nvd логотип

CVE-2022-2992

больше 3 лет назад

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS3: 9.9
EPSS: Критический
debian логотип

CVE-2022-2992

больше 3 лет назад

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prio ...

CVSS3: 9.9
EPSS: Критический
ubuntu логотип

CVE-2022-2931

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-2931

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-2931

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2908

больше 3 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-2908

больше 3 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-3060

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3060

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3060

Improper control of a resource identifier in Error Tracking in GitLab ...

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3031

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3031

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3031

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3030

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3030

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3030

An improper access control issue in GitLab CE/EE affecting all version ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3018

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3018

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3018

An information disclosure vulnerability in GitLab CE/EE affecting all ...

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2992

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS3: 9.9
94%
Критический
больше 3 лет назад
nvd логотип
CVE-2022-2992

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVSS3: 9.9
94%
Критический
больше 3 лет назад
debian логотип
CVE-2022-2992

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prio ...

CVSS3: 9.9
94%
Критический
больше 3 лет назад
ubuntu логотип
CVE-2022-2931

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2931

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2931

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2908

A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2908

A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу