Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2021-22260

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2021-22260

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the DataDog integration ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2021-22259

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22259

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22259

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting wit ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22258

больше 4 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22258

больше 4 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22258

больше 4 лет назад

The project import/export feature in GitLab 8.9 and greater could be u ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22257

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-22257

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-22257

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22256

больше 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-22256

больше 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-22256

больше 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 12 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22254

больше 4 лет назад

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-22254

больше 4 лет назад

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-22254

больше 4 лет назад

Under very specific conditions a user could be impersonated using Gitl ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22253

больше 4 лет назад

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2021-22253

больше 4 лет назад

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2021-22253

больше 4 лет назад

Improper authorization in GitLab EE affecting all versions since 13.4 ...

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-22260

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22260

A stored Cross-Site Scripting vulnerability in the DataDog integration ...

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting wit ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be u ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22256

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22256

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22256

Improper authorization in GitLab CE/EE affecting all versions since 12 ...

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22254

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22254

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22254

Under very specific conditions a user could be impersonated using Gitl ...

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22253

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

CVSS3: 4.9
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22253

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

CVSS3: 4.9
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22253

Improper authorization in GitLab EE affecting all versions since 13.4 ...

CVSS3: 4.9
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу