Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2021-39884

больше 4 лет назад

In all versions of GitLab EE since version 8.13, an endpoint discloses ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39883

больше 4 лет назад

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39883

больше 4 лет назад

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39883

больше 4 лет назад

Improper authorization checks in all versions of GitLab EE starting fr ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39882

больше 4 лет назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-39882

больше 4 лет назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-39882

больше 4 лет назад

In all versions of GitLab CE/EE, provided a user ID, anonymous users c ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2021-39881

больше 4 лет назад

In all versions of GitLab CE/EE since version 7.7, the application may ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39880

больше 4 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39880

больше 4 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39880

больше 4 лет назад

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39879

больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
EPSS: Низкий
nvd логотип

CVE-2021-39879

больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
EPSS: Низкий
debian логотип

CVE-2021-39879

больше 4 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7 ...

CVSS3: 2.2
EPSS: Низкий
ubuntu логотип

CVE-2021-39878

больше 4 лет назад

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2021-39878

больше 4 лет назад

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2021-39878

больше 4 лет назад

A stored Reflected Cross-Site Scripting vulnerability in the Jira inte ...

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2021-39877

больше 4 лет назад

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-39884

In all versions of GitLab EE since version 8.13, an endpoint discloses ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39883

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39883

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39883

Improper authorization checks in all versions of GitLab EE starting fr ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39882

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39882

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39882

In all versions of GitLab CE/EE, provided a user ID, anonymous users c ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39881

In all versions of GitLab CE/EE since version 7.7, the application may ...

CVSS3: 3.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39880

A Denial Of Service vulnerability in the apollo_upload_server Ruby gem ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39879

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39879

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS3: 2.2
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39879

Missing authentication in all versions of GitLab CE/EE since version 7 ...

CVSS3: 2.2
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39878

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

CVSS3: 5.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39878

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

CVSS3: 5.8
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39878

A stored Reflected Cross-Site Scripting vulnerability in the Jira inte ...

CVSS3: 5.8
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39877

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVSS3: 7.7
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу