Количество 5 336
Количество 5 336
CVE-2021-22178
An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.
CVE-2021-22178
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2021-22177
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.
CVE-2021-22177
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.
CVE-2021-22177
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 1 ...
CVE-2021-22176
An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests
CVE-2021-22176
An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests
CVE-2021-22176
An issue has been discovered in GitLab affecting all versions starting ...
CVE-2021-22175
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
CVE-2021-22175
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
CVE-2021-22175
When requests to the internal network for webhooks are enabled, a serv ...
CVE-2021-22172
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page
CVE-2021-22172
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page
CVE-2021-22172
Improper authorization in GitLab 12.8+ allows a guest user in a privat ...
CVE-2021-22171
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link
CVE-2021-22171
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link
CVE-2021-22171
Insufficient validation of authentication parameters in GitLab Pages f ...
CVE-2021-22170
Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content
CVE-2021-22170
Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content
CVE-2021-22170
Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-22178 An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration. | CVSS3: 5 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22178 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 5 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22177 Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command. | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22177 Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command. | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22177 Potential DoS was identified in gitlab-shell in GitLab CE/EE version 1 ... | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22176 An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22176 An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22176 An issue has been discovered in GitLab affecting all versions starting ... | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22175 When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled | CVSS3: 6.8 | 60% Средний | больше 4 лет назад | |
CVE-2021-22175 When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled | CVSS3: 6.8 | 60% Средний | больше 4 лет назад | |
CVE-2021-22175 When requests to the internal network for webhooks are enabled, a serv ... | CVSS3: 6.8 | 60% Средний | больше 4 лет назад | |
CVE-2021-22172 Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22172 Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22172 Improper authorization in GitLab 12.8+ allows a guest user in a privat ... | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
CVE-2021-22171 Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link | CVSS3: 7.3 | 0% Низкий | около 5 лет назад | |
CVE-2021-22171 Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link | CVSS3: 7.3 | 0% Низкий | около 5 лет назад | |
CVE-2021-22171 Insufficient validation of authentication parameters in GitLab Pages f ... | CVSS3: 7.3 | 0% Низкий | около 5 лет назад | |
CVE-2021-22170 Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content | CVSS3: 6.2 | 0% Низкий | около 4 лет назад | |
CVE-2021-22170 Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content | CVSS3: 6.2 | 0% Низкий | около 4 лет назад | |
CVE-2021-22170 Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows ... | CVSS3: 6.2 | 0% Низкий | около 4 лет назад |
Уязвимостей на страницу