Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2021-39911

больше 4 лет назад

An improper access control flaw in all versions of GitLab CE/EE starti ...

CVSS3: 1.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39910

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-39910

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2021-39910

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-39909

больше 4 лет назад

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-39909

больше 4 лет назад

Lack of email address ownership verification in the CODEOWNERS feature ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39908

около 4 лет назад

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39908

около 4 лет назад

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39908

около 4 лет назад

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39907

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-39907

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-39907

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE starting ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39906

больше 4 лет назад

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2021-39906

больше 4 лет назад

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2021-39906

больше 4 лет назад

Improper validation of ipynb files in GitLab CE/EE version 13.5 and ab ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39905

больше 4 лет назад

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39905

больше 4 лет назад

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39905

больше 4 лет назад

An information disclosure vulnerability in the GitLab CE/EE API since ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39904

больше 4 лет назад

An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39904

больше 4 лет назад

An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-39911

An improper access control flaw in all versions of GitLab CE/EE starti ...

CVSS3: 1.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39910

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39910

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39910

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39909

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39909

Lack of email address ownership verification in the CODEOWNERS feature ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39908

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-39908

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-39908

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-39907

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39907

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39907

A potential DOS vulnerability was discovered in GitLab CE/EE starting ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39906

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 8.7
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39906

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 8.7
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39906

Improper validation of ipynb files in GitLab CE/EE version 13.5 and ab ...

CVSS3: 8.7
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39905

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39905

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39905

An information disclosure vulnerability in the GitLab CE/EE API since ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39904

An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39904

An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request

CVSS3: 4.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу