Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2021-39888

больше 4 лет назад

In all versions of GitLab EE starting from 13.10 before 14.1.7, all ve ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39887

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2021-39887

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2021-39887

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Mar ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39886

больше 4 лет назад

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-39886

больше 4 лет назад

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2021-39886

больше 4 лет назад

Permissions rules were not applied while issues were moved between pro ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2021-39885

больше 4 лет назад

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2021-39885

больше 4 лет назад

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2021-39885

больше 4 лет назад

A Stored XSS in merge request creation page in all versions of Gitlab ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39884

больше 4 лет назад

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39884

больше 4 лет назад

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39884

больше 4 лет назад

In all versions of GitLab EE since version 8.13, an endpoint discloses ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39883

больше 4 лет назад

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39883

больше 4 лет назад

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39883

больше 4 лет назад

Improper authorization checks in all versions of GitLab EE starting fr ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39882

больше 4 лет назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-39882

больше 4 лет назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-39882

больше 4 лет назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users c ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-39888

In all versions of GitLab EE starting from 13.10 before 14.1.7, all ve ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39887

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39887

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39887

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Mar ...

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39886

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39886

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39886

Permissions rules were not applied while issues were moved between pro ...

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39885

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39885

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39885

A Stored XSS in merge request creation page in all versions of Gitlab ...

CVSS3: 8.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39884

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39884

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39884

In all versions of GitLab EE since version 8.13, an endpoint discloses ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39883

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39883

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39883

Improper authorization checks in all versions of GitLab EE starting fr ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39882

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39882

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39882

In all versions of GitLab CE/EE, provided a user ID, anonymous users c ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу