Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-1162

около 4 лет назад

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.1
EPSS: Высокий
nvd логотип

CVE-2022-1162

около 4 лет назад

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.1
EPSS: Высокий
debian логотип

CVE-2022-1162

около 4 лет назад

A hardcoded password was set for accounts registered using an OmniAuth ...

CVSS3: 9.1
EPSS: Высокий
ubuntu логотип

CVE-2022-1157

почти 4 года назад

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2022-1157

почти 4 года назад

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2022-1157

почти 4 года назад

Missing sanitization of logged exception messages in all versions prio ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2022-1148

около 4 лет назад

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1148

около 4 лет назад

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1148

около 4 лет назад

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1124

почти 4 года назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-1124

почти 4 года назад

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-1124

почти 4 года назад

An improper authorization issue has been discovered in GitLab CE/EE af ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1121

около 4 лет назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1121

около 4 лет назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1121

около 4 лет назад

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-1120

около 4 лет назад

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2022-1120

около 4 лет назад

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2022-1120

около 4 лет назад

Missing filtering in an error message in GitLab CE/EE affecting all ve ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2022-1111

около 4 лет назад

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
EPSS: Низкий
nvd логотип

CVE-2022-1111

около 4 лет назад

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.1
89%
Высокий
около 4 лет назад
nvd логотип
CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVSS3: 9.1
89%
Высокий
около 4 лет назад
debian логотип
CVE-2022-1162

A hardcoded password was set for accounts registered using an OmniAuth ...

CVSS3: 9.1
89%
Высокий
около 4 лет назад
ubuntu логотип
CVE-2022-1157

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.6
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1157

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

CVSS3: 2.6
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1157

Missing sanitization of logged exception messages in all versions prio ...

CVSS3: 2.6
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVSS3: 5.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affe ...

CVSS3: 5.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1124

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-1124

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-1124

An improper authorization issue has been discovered in GitLab CE/EE af ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/E ...

CVSS3: 5.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

CVSS3: 4.8
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all ve ...

CVSS3: 4.8
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-1111

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-1111

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.4
0%
Низкий
около 4 лет назад

Уязвимостей на страницу