Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

debian логотип

CVE-2021-22263

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22262

больше 4 лет назад

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-22262

больше 4 лет назад

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-22262

больше 4 лет назад

Missing access control in all GitLab versions starting from 13.12 befo ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22261

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2021-22261

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2021-22261

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22260

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2021-22260

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2021-22260

больше 4 лет назад

A stored Cross-Site Scripting vulnerability in the DataDog integration ...

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2021-22259

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22259

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22259

больше 4 лет назад

A potential DOS vulnerability was discovered in GitLab EE starting wit ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22258

больше 4 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22258

больше 4 лет назад

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22258

больше 4 лет назад

The project import/export feature in GitLab 8.9 and greater could be u ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22257

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-22257

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-22257

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22256

больше 4 лет назад

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22262

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22262

Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22262

Missing access control in all GitLab versions starting from 13.12 befo ...

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22261

A stored Cross-Site Scripting vulnerability in the Jira integration in ...

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22260

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22260

A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22260

A stored Cross-Site Scripting vulnerability in the DataDog integration ...

CVSS3: 7.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22259

A potential DOS vulnerability was discovered in GitLab EE starting wit ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22258

The project import/export feature in GitLab 8.9 and greater could be u ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22257

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22256

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

CVSS3: 5.4
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу