Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2022-2497

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2459

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2022-2459

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2022-2459

больше 3 лет назад

An issue has been discovered in GitLab EE affecting all versions befor ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2022-2456

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2022-2456

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2022-2456

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2022-2455

больше 3 лет назад

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-2455

больше 3 лет назад

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-2455

больше 3 лет назад

A business logic issue in the handling of large repositories in all ve ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2428

больше 3 лет назад

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-2428

больше 3 лет назад

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2022-2428

больше 3 лет назад

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2022-2417

больше 3 лет назад

Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2022-2417

больше 3 лет назад

Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.

CVSS3: 6.2
EPSS: Низкий
debian логотип

CVE-2022-2417

больше 3 лет назад

Insufficient validation in GitLab CE/EE affecting all versions from 12 ...

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2022-2326

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-2326

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2022-2326

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2022-2307

больше 3 лет назад

A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-2497

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.5
2%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2459

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2459

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2459

An issue has been discovered in GitLab EE affecting all versions befor ...

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2456

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request.

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2456

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request.

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2456

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2455

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2455

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2455

A business logic issue in the handling of large repositories in all ve ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2428

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2428

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2428

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting ...

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2417

Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2417

Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2417

Insufficient validation in GitLab CE/EE affecting all versions from 12 ...

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2326

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2326

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2326

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2307

A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу