Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

debian логотип

CVE-2021-22217

больше 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE befo ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22216

больше 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22216

больше 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-22216

больше 4 лет назад

A denial of service vulnerability in all versions of GitLab CE/EE befo ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22215

больше 4 лет назад

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-22215

больше 4 лет назад

An information disclosure vulnerability in GitLab EE versions 13.11 an ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22214

больше 4 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
EPSS: Критический
nvd логотип

CVE-2021-22214

больше 4 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
EPSS: Критический
debian логотип

CVE-2021-22214

больше 4 лет назад

When requests to the internal network for webhooks are enabled, a serv ...

CVSS3: 6.8
EPSS: Критический
ubuntu логотип

CVE-2021-22213

больше 4 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-22213

больше 4 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-22213

больше 4 лет назад

A cross-site leak vulnerability in the OAuth flow of all versions of G ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2021-22211

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-22211

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-22211

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22210

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-22210

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-22210

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22209

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-22209

почти 5 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-22217

A denial of service vulnerability in all versions of GitLab CE/EE befo ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22216

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22216

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22216

A denial of service vulnerability in all versions of GitLab CE/EE befo ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22215

An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22215

An information disclosure vulnerability in GitLab EE versions 13.11 an ...

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
94%
Критический
больше 4 лет назад
nvd логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVSS3: 6.8
94%
Критический
больше 4 лет назад
debian логотип
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a serv ...

CVSS3: 6.8
94%
Критический
больше 4 лет назад
ubuntu логотип
CVE-2021-22213

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22213

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22213

A cross-site leak vulnerability in the OAuth flow of all versions of G ...

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22211

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

CVSS3: 3.1
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22211

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

CVSS3: 3.1
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22211

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 3.1
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22210

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22210

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22210

An issue has been discovered in GitLab CE/EE affecting all versions st ...

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22209

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22209

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу