Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2022-0123

почти 4 года назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2022-0123

почти 4 года назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2022-0093

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-0093

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-0093

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0090

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-0090

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-0090

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-4191

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
EPSS: Критический
nvd логотип

CVE-2021-4191

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
EPSS: Критический
debian логотип

CVE-2021-4191

почти 4 года назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 t ...

CVSS3: 5.3
EPSS: Критический
ubuntu логотип

CVE-2021-39946

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2021-39946

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2021-39946

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39945

около 4 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2021-39945

около 4 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2021-39945

около 4 лет назад

Improper access control in the GitLab CE/EE API affecting all versions ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39944

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2021-39944

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2021-39944

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-0123

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 5.9
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0123

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 5.9
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0093

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0093

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0093

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 3.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
93%
Критический
почти 4 года назад
nvd логотип
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
93%
Критический
почти 4 года назад
debian логотип
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 t ...

CVSS3: 5.3
93%
Критический
почти 4 года назад
ubuntu логотип
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to ...

CVSS3: 8.7
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39945

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

CVSS3: 2.7
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39945

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

CVSS3: 2.7
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39945

Improper access control in the GitLab CE/EE API affecting all versions ...

CVSS3: 2.7
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

CVSS3: 7.1
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

CVSS3: 7.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.1
0%
Низкий
около 4 лет назад

Уязвимостей на страницу