Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2022-1426

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2
EPSS: Низкий
ubuntu логотип

CVE-2022-1423

почти 4 года назад

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2022-1423

почти 4 года назад

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2022-1423

почти 4 года назад

Improper access control in the CI/CD cache mechanism in GitLab CE/EE a ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2022-1417

почти 4 года назад

Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1417

почти 4 года назад

Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1417

почти 4 года назад

Improper access control in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1416

почти 4 года назад

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1416

почти 4 года назад

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1416

почти 4 года назад

Missing sanitization of data in Pipeline error messages in GitLab CE/E ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1413

почти 4 года назад

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-1413

почти 4 года назад

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-1413

почти 4 года назад

Missing input masking in GitLab CE/EE affecting all versions starting ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-1406

почти 4 года назад

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-1406

почти 4 года назад

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-1406

почти 4 года назад

Improper input validation in GitLab CE/EE affecting all versions from ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-1352

почти 4 года назад

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1352

почти 4 года назад

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1352

почти 4 года назад

Due to an insecure direct object reference vulnerability in Gitlab EE/ ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1193

почти 4 года назад

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-1426

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 2
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1423

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 7.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1423

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 7.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1423

Improper access control in the CI/CD cache mechanism in GitLab CE/EE a ...

CVSS3: 7.1
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1417

Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1417

Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1417

Improper access control in GitLab CE/EE affecting all versions startin ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1416

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1416

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1416

Missing sanitization of data in Pipeline error messages in GitLab CE/E ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1413

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 5.4
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1413

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

CVSS3: 5.4
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1413

Missing input masking in GitLab CE/EE affecting all versions starting ...

CVSS3: 5.4
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1406

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

CVSS3: 6.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1406

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

CVSS3: 6.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1406

Improper input validation in GitLab CE/EE affecting all versions from ...

CVSS3: 6.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1352

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1352

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1352

Due to an insecure direct object reference vulnerability in Gitlab EE/ ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1193

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVSS3: 4.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу