Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2021-22239

больше 4 лет назад

An unauthorized user was able to insert metadata when creating new iss ...

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2021-22238

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-22238

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2021-22238

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2021-22237

больше 4 лет назад

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2021-22237

больше 4 лет назад

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2021-22237

больше 4 лет назад

Under specialized conditions, GitLab may allow a user with an imperson ...

CVSS3: 6.6
EPSS: Низкий
ubuntu логотип

CVE-2021-22236

больше 4 лет назад

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2021-22236

больше 4 лет назад

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-22236

больше 4 лет назад

Due to improper handling of OAuth client IDs, new subscriptions genera ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22234

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2021-22234

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2021-22234

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 9.6
EPSS: Низкий
ubuntu логотип

CVE-2021-22233

больше 4 лет назад

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22233

больше 4 лет назад

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22233

больше 4 лет назад

An information disclosure vulnerability in GitLab EE versions 13.10 an ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22232

больше 4 лет назад

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2021-22232

больше 4 лет назад

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2021-22232

больше 4 лет назад

HTML injection was possible via the full name field before versions 13 ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22231

больше 4 лет назад

A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-22239

An unauthorized user was able to insert metadata when creating new iss ...

CVSS3: 5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22238

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

CVSS3: 6.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22238

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

CVSS3: 6.8
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22238

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22237

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

CVSS3: 6.6
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22237

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

CVSS3: 6.6
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22237

Under specialized conditions, GitLab may allow a user with an imperson ...

CVSS3: 6.6
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22236

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22236

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22236

Due to improper handling of OAuth client IDs, new subscriptions genera ...

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22234

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.

CVSS3: 9.6
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22234

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.

CVSS3: 9.6
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22234

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 9.6
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22233

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22233

An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22233

An information disclosure vulnerability in GitLab EE versions 13.10 an ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22232

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22232

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22232

HTML injection was possible via the full name field before versions 13 ...

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22231

A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

CVSS3: 3.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу