Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2022-0425

около 4 лет назад

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-0425

около 4 лет назад

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-0390

около 4 лет назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0390

около 4 лет назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0390

около 4 лет назад

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0373

около 4 лет назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0373

около 4 лет назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0373

около 4 лет назад

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0371

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0371

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0371

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0344

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-0344

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-0344

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2022-0283

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2022-0283

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2022-0283

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 13.5. ...

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2022-0249

около 4 лет назад

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-0249

около 4 лет назад

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-0249

около 4 лет назад

A vulnerability was discovered in GitLab starting with version 12. Git ...

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-0425

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0425

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0390

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0390

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0390

Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0373

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0373

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0373

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0371

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0371

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0371

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0344

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 3.1
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0344

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

CVSS3: 3.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0344

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 3.1
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0283

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 4.7
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0283

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

CVSS3: 4.7
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0283

An issue has been discovered affecting GitLab versions prior to 13.5. ...

CVSS3: 4.7
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0249

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0249

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0249

A vulnerability was discovered in GitLab starting with version 12. Git ...

CVSS3: 3.1
0%
Низкий
около 4 лет назад

Уязвимостей на страницу