Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-2527

больше 3 лет назад

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2022-2527

больше 3 лет назад

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-2527

больше 3 лет назад

An issue in Incident Timelines has been discovered in GitLab CE/EE aff ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2022-2512

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-2512

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-2512

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2501

больше 3 лет назад

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-2501

больше 3 лет назад

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2022-2501

больше 3 лет назад

An improper access control issue in GitLab EE affecting all versions f ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2022-2500

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2022-2500

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2022-2500

больше 3 лет назад

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2022-2499

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-2499

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-2499

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2498

больше 3 лет назад

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-2498

больше 3 лет назад

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2022-2498

больше 3 лет назад

An issue in pipeline subscriptions in GitLab EE affecting all versions ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2022-2497

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2022-2497

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-2527

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2527

An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2527

An issue in Incident Timelines has been discovered in GitLab CE/EE aff ...

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2512

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2512

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2512

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2501

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2501

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2501

An improper access control issue in GitLab EE affecting all versions f ...

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2500

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2500

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2500

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2499

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2499

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2499

An issue has been discovered in GitLab EE affecting all versions start ...

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2498

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2498

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2498

An issue in pipeline subscriptions in GitLab EE affecting all versions ...

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2497

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 8.5
2%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2497

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 8.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу