Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2021-22224

больше 4 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2021-22224

больше 4 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2021-22224

больше 4 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLa ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22223

больше 4 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-22223

больше 4 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-22223

больше 4 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE s ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22221

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22221

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-22221

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22220

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-22220

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-22220

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22219

больше 4 лет назад

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2021-22219

больше 4 лет назад

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2021-22219

больше 4 лет назад

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all ver ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22218

больше 4 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2021-22218

больше 4 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2021-22218

больше 4 лет назад

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all ve ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2021-22217

больше 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22217

больше 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-22224

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22224

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22224

A cross-site request forgery vulnerability in the GraphQL API in GitLa ...

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE s ...

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22220

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22220

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22220

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22219

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22219

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22219

All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all ver ...

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all ve ...

CVSS3: 2.6
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22217

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22217

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request

CVSS3: 6.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу