Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5 918

Количество 5 918

github логотип

GHSA-q99w-5q7g-6x5x

около 4 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q8qc-382x-cwgc

около 4 лет назад

Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).

EPSS: Низкий
github логотип

GHSA-q8cg-g95p-qfr2

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-q874-xrmj-fh8q

около 4 лет назад

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 4.8
EPSS: Средний
github логотип

GHSA-q84m-97hf-554f

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

EPSS: Низкий
github логотип

GHSA-q7qw-4c2f-p3rj

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

EPSS: Низкий
github логотип

GHSA-q7pq-xhw5-p4xw

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-q7jc-qjq2-4cmx

около 4 лет назад

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

EPSS: Низкий
github логотип

GHSA-q7hv-qq3g-4grg

больше 3 лет назад

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-q7f8-fr48-qw7g

больше 4 лет назад

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-q768-3m4h-qj2j

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-q757-g3qv-54vf

больше 4 лет назад

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q6vr-pm5m-w6c6

около 4 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

EPSS: Низкий
github логотип

GHSA-q6vm-3q95-jvvp

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-q6mw-555r-hgcg

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim's project.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-q6jf-84qm-cj59

около 4 лет назад

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

EPSS: Низкий
github логотип

GHSA-q6h4-g972-8qqw

около 4 лет назад

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

EPSS: Низкий
github логотип

GHSA-q656-cxxx-f8h7

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q5w6-p37j-cwr4

около 4 лет назад

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

EPSS: Низкий
github логотип

GHSA-q5jf-8f55-j92v

около 4 лет назад

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-q99w-5q7g-6x5x

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-q8qc-382x-cwgc

Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).

1%
Низкий
около 4 лет назад
github логотип
GHSA-q8cg-g95p-qfr2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction.

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-q874-xrmj-fh8q

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 4.8
56%
Средний
около 4 лет назад
github логотип
GHSA-q84m-97hf-554f

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

2%
Низкий
около 4 лет назад
github логотип
GHSA-q7qw-4c2f-p3rj

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

1%
Низкий
около 4 лет назад
github логотип
GHSA-q7pq-xhw5-p4xw

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

CVSS3: 4.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-q7jc-qjq2-4cmx

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

1%
Низкий
около 4 лет назад
github логотип
GHSA-q7hv-qq3g-4grg

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-q7f8-fr48-qw7g

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-q768-3m4h-qj2j

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-q757-g3qv-54vf

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-q6vr-pm5m-w6c6

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

1%
Низкий
около 4 лет назад
github логотип
GHSA-q6vm-3q95-jvvp

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-q6mw-555r-hgcg

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim's project.

CVSS3: 3.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-q6jf-84qm-cj59

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

1%
Низкий
около 4 лет назад
github логотип
GHSA-q6h4-g972-8qqw

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

1%
Низкий
около 4 лет назад
github логотип
GHSA-q656-cxxx-f8h7

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-q5w6-p37j-cwr4

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

1%
Низкий
около 4 лет назад
github логотип
GHSA-q5jf-8f55-j92v

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.