Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-2235

почти 4 года назад

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2022-2235

почти 4 года назад

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2022-2235

почти 4 года назад

Insufficient sanitization in GitLab EE's external issue tracker affect ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2022-2230

почти 4 года назад

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2022-2230

почти 4 года назад

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2022-2230

почти 4 года назад

A Stored Cross-Site Scripting vulnerability in the project settings pa ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2022-2229

почти 4 года назад

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-2229

почти 4 года назад

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-2229

почти 4 года назад

An improper authorization issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2228

почти 4 года назад

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-2228

почти 4 года назад

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-2228

почти 4 года назад

Information exposure in GitLab EE affecting all versions from 12.0 pri ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-2227

почти 4 года назад

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-2227

почти 4 года назад

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-2227

почти 4 года назад

Improper access control in the runner jobs API in GitLab CE/EE affecti ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-2185

почти 4 года назад

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVSS3: 9.9
EPSS: Критический
nvd логотип

CVE-2022-2185

почти 4 года назад

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVSS3: 9.9
EPSS: Критический
debian логотип

CVE-2022-2185

почти 4 года назад

A critical issue has been discovered in GitLab affecting all versions ...

CVSS3: 9.9
EPSS: Критический
ubuntu логотип

CVE-2022-2095

больше 3 лет назад

An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-2095

больше 3 лет назад

An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-2235

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 8.7
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2235

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 8.7
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2235

Insufficient sanitization in GitLab EE's external issue tracker affect ...

CVSS3: 8.7
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2230

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2230

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2230

A Stored Cross-Site Scripting vulnerability in the project settings pa ...

CVSS3: 8.1
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2229

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2229

An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2229

An improper authorization issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2228

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 5.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2228

Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range

CVSS3: 5.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2228

Information exposure in GitLab EE affecting all versions from 12.0 pri ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2227

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 3.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2227

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 3.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2227

Improper access control in the runner jobs API in GitLab CE/EE affecti ...

CVSS3: 3.1
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-2185

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVSS3: 9.9
90%
Критический
почти 4 года назад
nvd логотип
CVE-2022-2185

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVSS3: 9.9
90%
Критический
почти 4 года назад
debian логотип
CVE-2022-2185

A critical issue has been discovered in GitLab affecting all versions ...

CVSS3: 9.9
90%
Критический
почти 4 года назад
ubuntu логотип
CVE-2022-2095

An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2095

An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу