Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2022-1193

почти 4 года назад

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1193

почти 4 года назад

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1190

около 4 лет назад

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2022-1190

около 4 лет назад

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2022-1190

около 4 лет назад

Improper handling of user input in GitLab CE/EE versions 8.3 prior to ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2022-1189

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-1189

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-1189

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-1188

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2022-1188

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2022-1188

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2022-1185

около 4 лет назад

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-1185

около 4 лет назад

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-1185

около 4 лет назад

A denial of service vulnerability when rendering RDoc files in GitLab ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-1175

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS3: 8.7
EPSS: Средний
nvd логотип

CVE-2022-1175

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS3: 8.7
EPSS: Средний
debian логотип

CVE-2022-1175

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.4 be ...

CVSS3: 8.7
EPSS: Средний
ubuntu логотип

CVE-2022-1174

около 4 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1174

около 4 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1174

около 4 лет назад

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-1193

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1193

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1190

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 8.7
2%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1190

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

CVSS3: 8.7
2%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1190

Improper handling of user input in GitLab CE/EE versions 8.3 prior to ...

CVSS3: 8.7
2%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1189

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1189

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1189

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1188

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

CVSS3: 3.7
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1188

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

CVSS3: 3.7
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1188

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.7
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1185

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1185

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1185

A denial of service vulnerability when rendering RDoc files in GitLab ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1175

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS3: 8.7
10%
Средний
около 4 лет назад
nvd логотип
CVE-2022-1175

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS3: 8.7
10%
Средний
около 4 лет назад
debian логотип
CVE-2022-1175

Improper neutralization of user input in GitLab CE/EE versions 14.4 be ...

CVSS3: 8.7
10%
Средний
около 4 лет назад
ubuntu логотип
CVE-2022-1174

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1174

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1174

A potential DoS vulnerability was discovered in Gitlab CE/EE versions ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад

Уязвимостей на страницу