Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 332

Количество 5 332

github логотип

GHSA-mxgw-4fpv-6f32

больше 3 лет назад

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mxch-5ff5-jp4w

больше 3 лет назад

GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.

EPSS: Низкий
github логотип

GHSA-mx9x-fhqg-ggrp

12 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mx9j-jf6w-f9h8

больше 3 лет назад

An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.

EPSS: Низкий
github логотип

GHSA-mx6m-x365-fxj7

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-mwvc-fhmm-47cq

больше 3 лет назад

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-mw77-7v4x-3mh4

больше 3 лет назад

In all versions of GitLab EE since version 13.10, a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-mvf7-889j-9c49

больше 3 лет назад

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

EPSS: Низкий
github логотип

GHSA-mv85-vhf6-fp37

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-mrc8-h5gc-pvrr

больше 3 лет назад

A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos

EPSS: Низкий
github логотип

GHSA-mr7p-gv96-xc44

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-mr56-56j8-x6r4

около 2 лет назад

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-mqwr-4949-4hxc

больше 3 лет назад

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

EPSS: Низкий
github логотип

GHSA-mqhw-j2hw-86ff

почти 4 года назад

Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mqfg-2r7h-3f8c

больше 3 лет назад

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mqcw-437p-q69q

9 месяцев назад

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-mqc7-7g5h-6j4r

4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated requests.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-mq9g-jw9v-3pcf

больше 3 лет назад

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-mq5h-8f38-3xwp

4 месяца назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mq4m-g352-xm82

больше 2 лет назад

An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.

CVSS3: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mxgw-4fpv-6f32

Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mxch-5ff5-jp4w

GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mx9x-fhqg-ggrp

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.

CVSS3: 7.5
3%
Низкий
12 месяцев назад
github логотип
GHSA-mx9j-jf6w-f9h8

An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mx6m-x365-fxj7

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mwvc-fhmm-47cq

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-mw77-7v4x-3mh4

In all versions of GitLab EE since version 13.10, a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mvf7-889j-9c49

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mv85-vhf6-fp37

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mrc8-h5gc-pvrr

A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mr7p-gv96-xc44

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-mr56-56j8-x6r4

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-mqwr-4949-4hxc

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mqhw-j2hw-86ff

Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-mqfg-2r7h-3f8c

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mqcw-437p-q69q

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

CVSS3: 3.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-mqc7-7g5h-6j4r

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated requests.

CVSS3: 3.5
0%
Низкий
4 месяца назад
github логотип
GHSA-mq9g-jw9v-3pcf

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mq5h-8f38-3xwp

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-mq4m-g352-xm82

An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.

CVSS3: 2.6
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу