Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

ubuntu логотип

CVE-2021-39870

больше 4 лет назад

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39870

больше 4 лет назад

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39870

больше 4 лет назад

In all versions of GitLab CE/EE since version 11.11, an instance that ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39869

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39869

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39869

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.9, project exports may ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39868

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-39868

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-39868

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.12, an authenticated l ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-39867

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-39867

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-39867

больше 4 лет назад

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-39866

больше 4 лет назад

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-39866

больше 4 лет назад

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-39866

больше 4 лет назад

A business logic error in the project deletion process in GitLab 13.6 ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22264

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-22264

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2021-22264

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2021-22263

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2021-22263

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-39870

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39870

In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39870

In all versions of GitLab CE/EE since version 11.11, an instance that ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39869

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39869

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39869

In all versions of GitLab CE/EE since version 8.9, project exports may ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39868

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39868

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39868

In all versions of GitLab CE/EE since version 8.12, an authenticated l ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39867

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39867

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39867

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vu ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-39866

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-39866

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-39866

A business logic error in the project deletion process in GitLab 13.6 ...

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22264

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22264

An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22264

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу