Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2022-0136

около 4 лет назад

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-0125

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0125

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0125

около 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0124

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-0124

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0124

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0123

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-0123

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2022-0123

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2022-0093

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-0093

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-0093

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0090

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-0090

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-0090

около 4 лет назад

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-4191

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
EPSS: Критический
nvd логотип

CVE-2021-4191

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
EPSS: Критический
debian логотип

CVE-2021-4191

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting versions 13.0 t ...

CVSS3: 5.3
EPSS: Критический
ubuntu логотип

CVE-2021-39946

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-0136

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 ...

CVSS3: 5.4
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0125

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0125

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0125

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0124

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0124

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0124

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0123

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 5.9
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0123

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

CVSS3: 5.9
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0123

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 5.9
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0093

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0093

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0093

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 3.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5 ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
92%
Критический
около 4 лет назад
nvd логотип
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVSS3: 5.3
92%
Критический
около 4 лет назад
debian логотип
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 t ...

CVSS3: 5.3
92%
Критический
около 4 лет назад
ubuntu логотип
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
0%
Низкий
около 4 лет назад

Уязвимостей на страницу