Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2022-0489

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-0489

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-0489

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0488

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-0488

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-0488

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0477

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2022-0477

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2022-0477

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2022-0427

почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2022-0427

почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2022-0427

почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all ve ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2022-0425

почти 4 года назад

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-0425

почти 4 года назад

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-0390

почти 4 года назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0390

почти 4 года назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0390

почти 4 года назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0373

почти 4 года назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0373

почти 4 года назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0373

почти 4 года назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0488

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0488

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0488

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0477

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0477

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0477

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.9
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0427

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0427

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0427

Missing sanitization of HTML attributes in Jupyter notebooks in all ve ...

CVSS3: 7.7
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0425

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0425

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0390

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0390

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0390

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0373

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0373

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0373

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу