Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2021-39946

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2021-39946

около 4 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39945

больше 4 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2021-39945

больше 4 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2021-39945

больше 4 лет назад

Improper access control in the GitLab CE/EE API affecting all versions ...

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39944

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2021-39944

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2021-39944

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2021-39943

около 4 лет назад

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-39943

около 4 лет назад

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39943

около 4 лет назад

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39943

около 4 лет назад

An authorization logic error in the External Status Check API in GitLa ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39942

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39942

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39942

около 4 лет назад

A denial of service vulnerability in GitLab CE/EE affecting all versio ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39941

больше 4 лет назад

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2021-39941

больше 4 лет назад

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2021-39941

больше 4 лет назад

An information disclosure vulnerability in GitLab CE/EE versions 12.0 ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39940

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39940

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39946

Improper neutralization of user input in GitLab CE/EE versions 14.3 to ...

CVSS3: 8.7
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39945

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

CVSS3: 2.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39945

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

CVSS3: 2.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39945

Improper access control in the GitLab CE/EE API affecting all versions ...

CVSS3: 2.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39943

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-39943

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39943

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39943

An authorization logic error in the External Status Check API in GitLa ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versio ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39941

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

CVSS3: 3.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39941

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

CVSS3: 3.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39941

An information disclosure vulnerability in GitLab CE/EE versions 12.0 ...

CVSS3: 3.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39940

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39940

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу