Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2021-39943

около 4 лет назад

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-39943

около 4 лет назад

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39943

около 4 лет назад

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39943

около 4 лет назад

An authorization logic error in the External Status Check API in GitLa ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39942

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39942

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39942

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versio ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39941

около 4 лет назад

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2021-39941

около 4 лет назад

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2021-39941

около 4 лет назад

An information disclosure vulnerability in GitLab CE/EE versions 12.0 ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39940

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39940

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39940

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39939

около 4 лет назад

An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39939

около 4 лет назад

An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39939

около 4 лет назад

An uncontrolled resource consumption vulnerability in GitLab Runner af ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39938

около 4 лет назад

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-39938

около 4 лет назад

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-39938

около 4 лет назад

A vulnerable regular expression pattern in GitLab CE/EE since version ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-39937

около 4 лет назад

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-39943

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-39943

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39943

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39943

An authorization logic error in the External Status Check API in GitLa ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versio ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39941

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

CVSS3: 3.7
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39941

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

CVSS3: 3.7
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39941

An information disclosure vulnerability in GitLab CE/EE versions 12.0 ...

CVSS3: 3.7
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39940

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39940

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39940

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39939

An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39939

An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39939

An uncontrolled resource consumption vulnerability in GitLab Runner af ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39938

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

CVSS3: 3.1
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39938

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

CVSS3: 3.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39938

A vulnerable regular expression pattern in GitLab CE/EE since version ...

CVSS3: 3.1
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39937

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

CVSS3: 5.9
0%
Низкий
около 4 лет назад

Уязвимостей на страницу