Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 501

Количество 5 501

github логотип

GHSA-pcf2-p33r-6879

почти 4 года назад

An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email

EPSS: Низкий
github логотип

GHSA-p9w7-rqj5-fjh5

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p9m7-w29m-489v

почти 4 года назад

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

EPSS: Низкий
github логотип

GHSA-p9cp-qq4c-2wr5

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-p96p-59v7-xxp6

почти 3 года назад

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-p967-h43j-8p83

почти 4 года назад

In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p95h-29v8-j2h6

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p932-x66g-q6cc

больше 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-p7jp-3g8m-8m7m

почти 4 года назад

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

EPSS: Низкий
github логотип

GHSA-p7j7-2wwv-p5hw

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p7gw-xwgf-7w7c

3 месяца назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p79f-679r-6p3w

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-p6pm-7qxv-f8f3

больше 4 лет назад

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

EPSS: Низкий
github логотип

GHSA-p66q-2x4m-xxx9

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-p5m4-rr7j-g8gx

почти 4 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-p5fq-m9jh-pjrv

почти 3 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to commit to projects even from a restricted IP address.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p598-8v9q-qjhx

почти 4 года назад

In all versions of GitLab starting from 13.7, marshalled session keys were being stored in Redis.

EPSS: Низкий
github логотип

GHSA-p58m-cp94-fm4f

почти 4 года назад

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p4rh-pv9g-cw9x

почти 4 года назад

Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

EPSS: Низкий
github логотип

GHSA-p4cp-frqx-5q69

почти 4 года назад

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 10.8 prior to 14.8.5, and 10.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pcf2-p33r-6879

An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email

0%
Низкий
почти 4 года назад
github логотип
GHSA-p9w7-rqj5-fjh5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-p9m7-w29m-489v

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-p9cp-qq4c-2wr5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

CVSS3: 8.7
0%
Низкий
3 месяца назад
github логотип
GHSA-p96p-59v7-xxp6

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS3: 4.3
21%
Средний
почти 3 года назад
github логотип
GHSA-p967-h43j-8p83

In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-p95h-29v8-j2h6

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-p932-x66g-q6cc

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
3%
Низкий
больше 1 года назад
github логотип
GHSA-p7jp-3g8m-8m7m

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

0%
Низкий
почти 4 года назад
github логотип
GHSA-p7j7-2wwv-p5hw

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-p7gw-xwgf-7w7c

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-p79f-679r-6p3w

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-p6pm-7qxv-f8f3

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-p66q-2x4m-xxx9

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-p5m4-rr7j-g8gx

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-p5fq-m9jh-pjrv

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to commit to projects even from a restricted IP address.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-p598-8v9q-qjhx

In all versions of GitLab starting from 13.7, marshalled session keys were being stored in Redis.

0%
Низкий
почти 4 года назад
github логотип
GHSA-p58m-cp94-fm4f

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-p4rh-pv9g-cw9x

Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

0%
Низкий
почти 4 года назад
github логотип
GHSA-p4cp-frqx-5q69

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 10.8 prior to 14.8.5, and 10.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVSS3: 4.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу