Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2022-0371

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0371

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0371

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0344

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-0344

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-0344

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-0283

почти 4 года назад

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2022-0283

почти 4 года назад

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2022-0283

почти 4 года назад

An issue has been discovered affecting GitLab versions prior to 13.5. ...

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2022-0249

почти 4 года назад

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-0249

почти 4 года назад

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-0249

почти 4 года назад

A vulnerability was discovered in GitLab starting with version 12. Git ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-0244

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2022-0244

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-0244

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2022-0172

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-0172

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-0172

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0167

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-0167

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-0371

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0371

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0371

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0344

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 3.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0344

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 3.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0344

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0283

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 4.7
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0283

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 4.7
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0283

An issue has been discovered affecting GitLab versions prior to 13.5. ...

CVSS3: 4.7
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0249

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 3.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0249

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 3.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0249

A vulnerability was discovered in GitLab starting with version 12. Git ...

CVSS3: 3.1
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0244

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

CVSS3: 8.6
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0244

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

CVSS3: 8.6
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0244

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 8.6
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0172

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0172

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0172

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0167

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-0167

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу