Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2021-39868

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.12, an authenticated l ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39867

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39867

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39867

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39866

больше 4 лет назад

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-39866

больше 4 лет назад

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-39866

больше 4 лет назад

A business logic error in the project deletion process in GitLab 13.6 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22264

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-22264

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2021-22264

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2021-22263

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2021-22263

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-22263

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22262

больше 4 лет назад

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-22262

больше 4 лет назад

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-22262

больше 4 лет назад

Missing access control in all GitLab versions starting from 13.12 befo ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22261

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2021-22261

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2021-22261

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22260

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-39868

In all versions of GitLab CE/EE since version 8.12, an authenticated l ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39867

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39867

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39867

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39866

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39866

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39866

A business logic error in the project deletion process in GitLab 13.6 ...

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22264

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22264

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22264

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22262

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22262

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22262

Missing access control in all GitLab versions starting from 13.12 befo ...

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in ...

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22260

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 7.7
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу