Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2022-2908

больше 3 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-2907

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2022-2907

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2022-2907

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2022-2904

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2022-2904

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-2904

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2022-2884

больше 3 лет назад

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
EPSS: Средний
nvd логотип

CVE-2022-2884

больше 3 лет назад

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
EPSS: Средний
debian логотип

CVE-2022-2884

больше 3 лет назад

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 pri ...

CVSS3: 9.9
EPSS: Средний
ubuntu логотип

CVE-2022-2882

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-2882

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-2882

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2865

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2022-2865

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-2865

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2022-2826

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. TODO

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2022-2826

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. TODO

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2022-2826

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2022-2761

больше 3 лет назад

An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-2908

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2907

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link.

CVSS3: 5.7
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-2907

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link.

CVSS3: 5.7
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-2907

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.7
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-2904

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
5%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2904

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
5%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2904

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
5%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2884

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
68%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-2884

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS3: 9.9
68%
Средний
больше 3 лет назад
debian логотип
CVE-2022-2884

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 pri ...

CVSS3: 9.9
68%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2022-2882

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2882

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2882

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2865

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2865

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2865

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2826

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. TODO

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2826

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. TODO

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2826

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2761

An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу