Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39880

больше 4 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39880

больше 4 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39880

больше 4 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39879

больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
EPSS: Низкий
nvd логотип

CVE-2021-39879

больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
EPSS: Низкий
debian логотип

CVE-2021-39879

больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7 ...

CVSS3: 2.2
EPSS: Низкий
ubuntu логотип

CVE-2021-39878

больше 4 лет назад

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2021-39878

больше 4 лет назад

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2021-39878

больше 4 лет назад

A stored Reflected Cross-Site Scripting vulnerability in the Jira inte ...

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2021-39877

больше 4 лет назад

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2021-39877

больше 4 лет назад

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2021-39877

больше 4 лет назад

A vulnerability was discovered in GitLab starting with version 12.2 th ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39876

почти 4 года назад

In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39876

почти 4 года назад

In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39876

почти 4 года назад

In all versions of GitLab CE/EE since version 11.3, the endpoint for a ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39875

больше 4 лет назад

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-39875

больше 4 лет назад

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-39875

больше 4 лет назад

In all versions of GitLab CE/EE since version 13.6, it is possible to ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may ...

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39879

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39879

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39879

Missing authentication in all versions of GitLab CE/EE since version 7 ...

CVSS3: 2.2
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39878

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

CVSS3: 5.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39878

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

CVSS3: 5.8
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39878

A stored Reflected Cross-Site Scripting vulnerability in the Jira inte ...

CVSS3: 5.8
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39877

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39877

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39877

A vulnerability was discovered in GitLab starting with version 12.2 th ...

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39876

In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-39876

In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-39876

In all versions of GitLab CE/EE since version 11.3, the endpoint for a ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2021-39875

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39875

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39875

In all versions of GitLab CE/EE since version 13.6, it is possible to ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу