Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2022-2307

больше 3 лет назад

A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-2307

больше 3 лет назад

A lack of cascading deletes in GitLab CE/EE affecting all versions sta ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2303

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-2303

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-2303

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-2281

почти 4 года назад

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2022-2281

почти 4 года назад

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2022-2281

почти 4 года назад

An information disclosure vulnerability in GitLab EE affecting all ver ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2022-2270

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-2270

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-2270

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2250

почти 4 года назад

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2022-2250

почти 4 года назад

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2022-2250

почти 4 года назад

An open redirect vulnerability in GitLab EE/CE affecting all versions ...

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2022-2244

почти 4 года назад

An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-2244

почти 4 года назад

An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-2244

почти 4 года назад

An improper authorization vulnerability in GitLab EE/CE affecting all ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-2243

почти 4 года назад

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2022-2243

почти 4 года назад

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2022-2243

почти 4 года назад

An access control vulnerability in GitLab EE/CE affecting all versions ...

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-2307

A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2307

A lack of cascading deletes in GitLab CE/EE affecting all versions sta ...

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2303

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2303

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2303

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-2281

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 2.6
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2281

An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases.

CVSS3: 2.6
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2281

An information disclosure vulnerability in GitLab EE affecting all ver ...

CVSS3: 2.6
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2270

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2270

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2270

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2250

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 4.7
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2250

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS3: 4.7
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2250

An open redirect vulnerability in GitLab EE/CE affecting all versions ...

CVSS3: 4.7
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2244

An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2244

An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2244

An improper authorization vulnerability in GitLab EE/CE affecting all ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2243

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2243

An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.

CVSS3: 5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2243

An access control vulnerability in GitLab EE/CE affecting all versions ...

CVSS3: 5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу