Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2021-39894

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-39894

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-39894

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vul ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-39893

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-39893

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-39893

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab starting with v ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39892

около 4 лет назад

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39892

около 4 лет назад

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39892

около 4 лет назад

In all versions of GitLab CE/EE since version 12.0, a lower privileged ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39891

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2021-39891

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2021-39891

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.0, access tokens creat ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2021-39890

около 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-39890

около 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-39890

около 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-39889

больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39889

больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39889

больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure di ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39888

больше 4 лет назад

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39888

больше 4 лет назад

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-39894

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39894

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39894

In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vul ...

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39893

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39893

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39893

A potential DOS vulnerability was discovered in GitLab starting with v ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39892

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39892

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39892

In all versions of GitLab CE/EE since version 12.0, a lower privileged ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39891

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 5.9
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39891

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 5.9
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39891

In all versions of GitLab CE/EE since version 8.0, access tokens creat ...

CVSS3: 5.9
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific ...

CVSS3: 3.1
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure di ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39888

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39888

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу