Количество 5 336
Количество 5 336
CVE-2022-1148
Improper authorization in GitLab Pages included with GitLab CE/EE affe ...
CVE-2022-1124
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
CVE-2022-1124
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
CVE-2022-1124
An improper authorization issue has been discovered in GitLab CE/EE af ...
CVE-2022-1121
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.
CVE-2022-1121
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.
CVE-2022-1121
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...
CVE-2022-1120
Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.
CVE-2022-1120
Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.
CVE-2022-1120
Missing filtering in an error message in GitLab CE/EE affecting all ve ...
CVE-2022-1111
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
CVE-2022-1111
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
CVE-2022-1111
A business logic error in Project Import in GitLab CE/EE versions 14.9 ...
CVE-2022-1105
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled
CVE-2022-1105
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled
CVE-2022-1105
An improper access control vulnerability in GitLab CE/EE affecting all ...
CVE-2022-1100
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.
CVE-2022-1100
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.
CVE-2022-1100
A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...
CVE-2022-1099
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-1148 Improper authorization in GitLab Pages included with GitLab CE/EE affe ... | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1124 An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1124 An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1124 An improper authorization issue has been discovered in GitLab CE/EE af ... | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1121 A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1121 A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1121 A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ... | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1120 Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration. | CVSS3: 4.8 | 0% Низкий | почти 4 года назад | |
CVE-2022-1120 Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration. | CVSS3: 4.8 | 0% Низкий | почти 4 года назад | |
CVE-2022-1120 Missing filtering in an error message in GitLab CE/EE affecting all ve ... | CVSS3: 4.8 | 0% Низкий | почти 4 года назад | |
CVE-2022-1111 A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages | CVSS3: 2.4 | 0% Низкий | почти 4 года назад | |
CVE-2022-1111 A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages | CVSS3: 2.4 | 0% Низкий | почти 4 года назад | |
CVE-2022-1111 A business logic error in Project Import in GitLab CE/EE versions 14.9 ... | CVSS3: 2.4 | 0% Низкий | почти 4 года назад | |
CVE-2022-1105 An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1105 An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1105 An improper access control vulnerability in GitLab CE/EE affecting all ... | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1100 A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1100 A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1100 A potential DOS vulnerability was discovered in GitLab CE/EE affecting ... | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1099 Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab | CVSS3: 4.3 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу