Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-1545

почти 4 года назад

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1545

почти 4 года назад

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1545

почти 4 года назад

It was possible to disclose details of confidential notes created via ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1510

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-1510

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-1510

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-1460

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-1460

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-1460

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2022-1433

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2022-1433

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2022-1433

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2022-1431

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1431

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1431

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1428

почти 4 года назад

An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1428

почти 4 года назад

An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1428

почти 4 года назад

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1426

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

CVSS3: 2
EPSS: Низкий
nvd логотип

CVE-2022-1426

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

CVSS3: 2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-1545

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1545

It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1545

It was possible to disclose details of confidential notes created via ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1510

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1510

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1510

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1460

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1460

An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1460

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.1
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1433

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 2.6
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1433

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

CVSS3: 2.6
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1433

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2.6
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1431

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1431

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1431

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1428

An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1428

An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1428

An issue has been discovered in GitLab affecting all versions before 1 ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1426

An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

CVSS3: 2
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1426

An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

CVSS3: 2
0%
Низкий
почти 4 года назад

Уязвимостей на страницу