Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2022-0738

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2022-0738

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.2
EPSS: Низкий
ubuntu логотип

CVE-2022-0735

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 10
EPSS: Средний
nvd логотип

CVE-2022-0735

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 10
EPSS: Средний
debian логотип

CVE-2022-0735

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 10
EPSS: Средний
ubuntu логотип

CVE-2022-0549

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-0549

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-0549

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0489

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-0489

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-0489

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0488

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-0488

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-0488

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0477

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2022-0477

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2022-0477

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2022-0427

около 4 лет назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2022-0427

около 4 лет назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2022-0427

около 4 лет назад

Missing sanitization of HTML attributes in Jupyter notebooks in all ve ...

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-0738

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.

CVSS3: 4.2
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0738

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.2
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0735

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 10
57%
Средний
около 4 лет назад
nvd логотип
CVE-2022-0735

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVSS3: 10
57%
Средний
около 4 лет назад
debian логотип
CVE-2022-0735

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 10
57%
Средний
около 4 лет назад
ubuntu логотип
CVE-2022-0549

An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0549

An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0549

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0488

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0488

An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0488

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0477

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0477

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0477

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.9
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0427

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0427

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 7.7
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0427

Missing sanitization of HTML attributes in Jupyter notebooks in all ve ...

CVSS3: 7.7
0%
Низкий
около 4 лет назад

Уязвимостей на страницу