Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2021-39890

больше 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-39890

больше 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-39890

больше 4 лет назад

It was possible to bypass 2FA for LDAP users and access some specific ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-39889

больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39889

больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39889

больше 4 лет назад

In all versions of GitLab EE since version 14.1, due to an insecure di ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39888

больше 4 лет назад

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39888

больше 4 лет назад

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39888

больше 4 лет назад

In all versions of GitLab EE starting from 13.10 before 14.1.7, all ve ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39887

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2021-39887

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2021-39887

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Mar ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39886

больше 4 лет назад

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-39886

больше 4 лет назад

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2021-39886

больше 4 лет назад

Permissions rules were not applied while issues were moved between pro ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2021-39885

больше 4 лет назад

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2021-39885

больше 4 лет назад

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2021-39885

больше 4 лет назад

A Stored XSS in merge request creation page in all versions of Gitlab ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2021-39884

больше 4 лет назад

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39884

больше 4 лет назад

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific ...

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39889

In all versions of GitLab EE since version 14.1, due to an insecure di ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39888

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39888

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39888

In all versions of GitLab EE starting from 13.10 before 14.1.7, all ve ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39887

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39887

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39887

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Mar ...

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39886

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39886

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39886

Permissions rules were not applied while issues were moved between pro ...

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39885

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39885

A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names

CVSS3: 8.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39885

A Stored XSS in merge request creation page in all versions of Gitlab ...

CVSS3: 8.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39884

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39884

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу