Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2022-1148

почти 4 года назад

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1124

почти 4 года назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1124

почти 4 года назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1124

почти 4 года назад

An improper authorization issue has been discovered in GitLab CE/EE af ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1121

почти 4 года назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1121

почти 4 года назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1121

почти 4 года назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1120

почти 4 года назад

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2022-1120

почти 4 года назад

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2022-1120

почти 4 года назад

Missing filtering in an error message in GitLab CE/EE affecting all ve ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2022-1111

почти 4 года назад

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
EPSS: Низкий
nvd логотип

CVE-2022-1111

почти 4 года назад

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
EPSS: Низкий
debian логотип

CVE-2022-1111

почти 4 года назад

A business logic error in Project Import in GitLab CE/EE versions 14.9 ...

CVSS3: 2.4
EPSS: Низкий
ubuntu логотип

CVE-2022-1105

почти 4 года назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1105

почти 4 года назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1105

почти 4 года назад

An improper access control vulnerability in GitLab CE/EE affecting all ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1100

почти 4 года назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1100

почти 4 года назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1100

почти 4 года назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1099

почти 4 года назад

Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1124

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1124

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1124

An improper authorization issue has been discovered in GitLab CE/EE af ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all ve ...

CVSS3: 4.8
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1111

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1111

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1111

A business logic error in Project Import in GitLab CE/EE versions 14.9 ...

CVSS3: 2.4
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1105

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1105

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1105

An improper access control vulnerability in GitLab CE/EE affecting all ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1100

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1100

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1100

A potential DOS vulnerability was discovered in GitLab CE/EE affecting ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1099

Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

CVSS3: 4.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу