Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-q49w-v89m-366g

почти 4 года назад

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

EPSS: Низкий
github логотип

GHSA-q477-jxcv-9pxw

почти 4 года назад

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

EPSS: Низкий
github логотип

GHSA-q439-vprm-5c8j

почти 4 года назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-q3qh-rxpm-hmc7

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

EPSS: Низкий
github логотип

GHSA-q35c-75fc-6v95

больше 3 лет назад

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q2f3-hg8j-4wcc

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-q297-5xx3-gw53

почти 4 года назад

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

EPSS: Низкий
github логотип

GHSA-q28r-ggr6-763f

больше 1 года назад

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q242-rh63-p6m2

почти 4 года назад

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-pxc9-3wm8-wgmr

почти 4 года назад

An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-px82-82wp-3w57

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-px4x-cjpp-hqv5

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pwvw-rggj-f74r

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-pwp8-jvcw-f7w4

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-pw3w-gf65-52v7

почти 4 года назад

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

EPSS: Низкий
github логотип

GHSA-pvxr-g7hw-fv88

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-pvxf-9mm4-92xf

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-pvq4-gmpq-27p3

больше 1 года назад

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-pvm7-rp3m-8gh2

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-pv96-f897-xcch

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API endpoint even when repository access was disabled.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-q49w-v89m-366g

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-q477-jxcv-9pxw

An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

0%
Низкий
почти 4 года назад
github логотип
GHSA-q439-vprm-5c8j

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-q3qh-rxpm-hmc7

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-q35c-75fc-6v95

Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q2f3-hg8j-4wcc

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-q297-5xx3-gw53

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

0%
Низкий
почти 4 года назад
github логотип
GHSA-q28r-ggr6-763f

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-q242-rh63-p6m2

An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-pxc9-3wm8-wgmr

An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-px82-82wp-3w57

An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-px4x-cjpp-hqv5

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-pwvw-rggj-f74r

An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-pwp8-jvcw-f7w4

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

0%
Низкий
почти 4 года назад
github логотип
GHSA-pw3w-gf65-52v7

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

0%
Низкий
почти 4 года назад
github логотип
GHSA-pvxr-g7hw-fv88

An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.

CVSS3: 5
0%
Низкий
8 месяцев назад
github логотип
GHSA-pvxf-9mm4-92xf

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.

CVSS3: 7.3
3%
Низкий
почти 2 года назад
github логотип
GHSA-pvq4-gmpq-27p3

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-pvm7-rp3m-8gh2

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pv96-f897-xcch

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API endpoint even when repository access was disabled.

CVSS3: 5.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу