Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2021-39937

около 4 лет назад

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2021-39937

около 4 лет назад

A collision in access memoization logic in all versions of GitLab CE/E ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2021-39936

около 4 лет назад

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2021-39936

около 4 лет назад

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2021-39936

около 4 лет назад

Improper access control in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39935

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS3: 6.8
EPSS: Средний
nvd логотип

CVE-2021-39935

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS3: 6.8
EPSS: Средний
debian логотип

CVE-2021-39935

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.8
EPSS: Средний
ubuntu логотип

CVE-2021-39934

около 4 лет назад

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39934

около 4 лет назад

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39934

около 4 лет назад

Improper access control allows any project member to retrieve the serv ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39933

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39933

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39933

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39932

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39932

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39932

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39931

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-39931

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-39931

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-39937

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

CVSS3: 5.9
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39937

A collision in access memoization logic in all versions of GitLab CE/E ...

CVSS3: 5.9
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39936

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39936

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39936

Improper access control in GitLab CE/EE affecting all versions startin ...

CVSS3: 3.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS3: 6.8
53%
Средний
около 4 лет назад
nvd логотип
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS3: 6.8
53%
Средний
около 4 лет назад
debian логотип
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 6.8
53%
Средний
около 4 лет назад
ubuntu логотип
CVE-2021-39934

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39934

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39934

Improper access control allows any project member to retrieve the serv ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39933

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39933

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39933

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39932

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39932

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39932

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39931

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39931

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39931

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
0%
Низкий
около 4 лет назад

Уязвимостей на страницу