Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2021-22178

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2021-22178

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2021-22177

почти 5 лет назад

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22177

почти 5 лет назад

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22177

почти 5 лет назад

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 1 ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22176

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22176

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22176

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22175

больше 4 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVSS3: 6.8
EPSS: Средний
nvd логотип

CVE-2021-22175

больше 4 лет назад

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVSS3: 6.8
EPSS: Средний
debian логотип

CVE-2021-22175

больше 4 лет назад

When requests to the internal network for webhooks are enabled, a serv ...

CVSS3: 6.8
EPSS: Средний
ubuntu логотип

CVE-2021-22172

почти 5 лет назад

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22172

почти 5 лет назад

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22172

почти 5 лет назад

Improper authorization in GitLab 12.8+ allows a guest user in a privat ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22171

около 5 лет назад

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2021-22171

около 5 лет назад

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2021-22171

около 5 лет назад

Insufficient validation of authentication parameters in GitLab Pages f ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22170

около 4 лет назад

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2021-22170

около 4 лет назад

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 6.2
EPSS: Низкий
debian логотип

CVE-2021-22170

около 4 лет назад

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows ...

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-22178

An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.

CVSS3: 5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22178

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 5
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22177

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22177

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22177

Potential DoS was identified in gitlab-shell in GitLab CE/EE version 1 ...

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22176

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22176

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22176

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22175

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVSS3: 6.8
60%
Средний
больше 4 лет назад
nvd логотип
CVE-2021-22175

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVSS3: 6.8
60%
Средний
больше 4 лет назад
debian логотип
CVE-2021-22175

When requests to the internal network for webhooks are enabled, a serv ...

CVSS3: 6.8
60%
Средний
больше 4 лет назад
ubuntu логотип
CVE-2021-22172

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22172

Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22172

Improper authorization in GitLab 12.8+ allows a guest user in a privat ...

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22171

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

CVSS3: 7.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-22171

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

CVSS3: 7.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2021-22171

Insufficient validation of authentication parameters in GitLab Pages f ...

CVSS3: 7.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-22170

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 6.2
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-22170

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

CVSS3: 6.2
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-22170

Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows ...

CVSS3: 6.2
0%
Низкий
около 4 лет назад

Уязвимостей на страницу